CVE-2023-39965Medium· 6.5▾ Sunlit1Panel Arbitrary File Download vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Any file downloading vulnerability exists in 1Panel backend.
Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access.

payload:
POST /api/v1/files/download/bypath HTTP/1.1 Host: ip Content-Type: application/json
{"path":"/etc/passwd"}

Attackers can freely download the file content on the target system. This will be caused a large amount of information leakage.
github.com/1Panel-dev/1Panel >= 1.4.3, < 1.5.0Upgrade to a patched release:
github.com/1Panel-dev/1Panel 1.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
CVE-2024-39907Critical· 9.81Panel has an SQL injection issue related to the orderBy clause
CVE-2024-27288Medium· 6.31Panel open source panel project has an unauthorized vulnerability.
CVE-2026-79919Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-79918Medium· 6.3MaxKB is an open-source AI assistant for enterprise