Record summary

CVE-2023-39964 has a selected CVSS score of 7.5 (high).

Description

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`, which directly reads the file by obtaining the requested path `parameter[path]`. The request parameters are not filtered, resulting in a background arbitrary file reading vulnerability. Version 1.5.0 has a patch for this issue.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 6, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List= 1.4.3affected

Default status: unknown

CVE List, VulnCheck1.4.3affected

github.com/1Panel-dev/1Panel

Browse Go / github.com/1Panel-dev/1Panel
GitHub Advisory1.4.3affected
1.4.3 to < 1.5.0 · Fixed in 1.5.0affected

References

4