CVE-2025-66292

Aliases:GHSA-vh2x-fw87-4fxqGO-2026-4318
Advisory lineage Upstream: 0 Downstream: 1
Analyzed
Published: 15 Jan 2026, 16:19
Last modified:15 Jan 2026, 16:44

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
0.07% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

15 Jan 2026, 16:19
Published
Vulnerability first disclosed
15 Jan 2026, 16:44
Last Modified
Vulnerability information updated

Description

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into the administrative backend, this interface can be used to delete files. The vulnerability lies in the Delete function within the app/common/http/controller/attach.go file. The path parameter submitted by the user is directly passed to storage.Local{}.GetSaveRealPath and subsequently to os.Remove without proper sanitization or checking for path traversal characters (../). And the helper function in common/service/storage/local.go uses filepath.Join, which resolves ../ but does not enforce a chroot/jail. This vulnerability is fixed in 1.9.2.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

  • CWE-73External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

Affected Systems

  • donknapdpanel

    < 1.9.2

  • dpaneldpanel

    < 1.9.2

  • github.com/donknapdpanel

    < 1.9.2

References (5)