Vulnerability record · CVE-2025-54424 · published 1 August 2025
CVE-2025-54424: Fit2cloud 1panel command injection vulnerability
Fit2cloud · 1panel
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during certificate validation, leading to unauthorized interface access. Due to the presence of numerous command execution or high-privilege interfaces in 1Panel, this results in Remote Code Execution (RCE). This is fixed in version 2.0.6. The CVE has been translated from Simplified Chinese using GitHub Copilot.
Description
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during certificate validation, leading to unauthorized interface access. Due to the presence of numerous command execution or high-privilege interfaces in 1Panel, this results in Remote Code Execution (RCE). This is fixed in version 2.0.6. The CVE has been translated from Simplified Chinese using GitHub Copilot.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/1Panel-dev/1Panel/pull/9698/commits/4003284521f8d31ddaf7215d1c30ab8b4cdb0261 | Patch |
| https://github.com/1Panel-dev/1Panel/releases/tag/v2.0.6 | Release Notes |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-8j63-96wh-wh3j | ExploitThird Party Advisory |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-8j63-96wh-wh3j | ExploitThird Party Advisory |
Track CVE-2025-54424 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-54424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.