Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vh2x-fw87-4fxq | DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface |
Thu, 12 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dpanel
Dpanel dpanel |
|
| CPEs | cpe:2.3:a:dpanel:dpanel:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Dpanel
Dpanel dpanel |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Donknap
Donknap dpanel |
|
| Vendors & Products |
Donknap
Donknap dpanel |
Thu, 15 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into the administrative backend, this interface can be used to delete files. The vulnerability lies in the Delete function within the app/common/http/controller/attach.go file. The path parameter submitted by the user is directly passed to storage.Local{}.GetSaveRealPath and subsequently to os.Remove without proper sanitization or checking for path traversal characters (../). And the helper function in common/service/storage/local.go uses filepath.Join, which resolves ../ but does not enforce a chroot/jail. This vulnerability is fixed in 1.9.2. | |
| Title | DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-15T16:44:51.018Z
Reserved: 2025-11-26T23:11:46.392Z
Link: CVE-2025-66292
Updated: 2026-01-15T16:44:47.479Z
Status : Analyzed
Published: 2026-01-15T17:16:04.570
Modified: 2026-03-12T18:07:07.010
Link: CVE-2025-66292
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:43:51Z
Github GHSA