1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qmg5-v42x-qqhq 1Panel – CAPTCHA Bypass via Client-Controlled Flag
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Fit2cloud
Fit2cloud 1panel
CPEs cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*
Vendors & Products Fit2cloud
Fit2cloud 1panel

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared 1panel
1panel 1panel
Linux
Linux linux
Vendors & Products 1panel
1panel 1panel
Linux
Linux linux

Tue, 09 Dec 2025 02:00:00 +0000

Type Values Removed Values Added
Description 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
Title 1Panel – CAPTCHA Bypass via Client-Controlled Flag
Weaknesses CWE-290
CWE-602
CWE-807
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-09T16:03:18.696Z

Reserved: 2025-12-03T15:12:22.978Z

Link: CVE-2025-66507

cve-icon Vulnrichment

Updated: 2025-12-09T14:17:22.158Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T16:18:19.270

Modified: 2025-12-10T21:28:33.877

Link: CVE-2025-66507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T10:04:28Z

Weaknesses