Impact
OpenPanel writes Model Context Protocol authentication tokens from URL query parameters into plaintext application logs without redaction, allowing anyone with access to the logs to retrieve base64‑encoded credentials. Capturing these tokens lets an attacker replay MCP requests and access project analytics, compromising the confidentiality of authentication credentials and the integrity of analytical data. This weakness is classified as CWE-532, improper logging of sensitive information.
Affected Systems
The vulnerability affects OpenPanel versions 2.3.0 and earlier. Any deployment of OpenPanel built on or before version 2.3.0 is considered affected. No newer release has been identified to address this issue.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity, and with an EPSS score of < 1% the exploitation probability is very low. Attackers must have read access to the application’s standard output or centralized logging environment to exploit the flaw, which typically requires an insider or a compromised logging system. While the risk is moderate, the potential impact on credential confidentiality and analytical data integrity warrants prompt attention. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment