
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66292 is an arbitrary file deletion vulnerability via path traversal in DPanel, an open-source Docker management panel written in Go. It affects all DPanel versions prior to 1.9.2 and was disclosed on January 15, 2026, via a GitHub Security Advisory. Authenticated users can exploit the /api/common/attach/delete interface to delete arbitrary files on the server by supplying path traversal sequences in the path parameter. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory).
The root cause is improper path validation (CWE-22: Path Traversal; CWE-73: External Control of File Name or Path) in the Delete function within app/common/http/controller/attach.go. The user-supplied path parameter is passed directly to storage.Local{}.GetSaveRealPath() and subsequently to os.Remove() without sanitization or validation of traversal characters (../). The helper function in common/service/storage/local.go uses Go's filepath.Join, which resolves ../ sequences but does not enforce a chroot or jail boundary, allowing the resolved path to escape the intended storage directory. The fix in commit cbda0d9 adds a filepath.IsLocal() check and filepath.Clean() call before processing the path, rejecting any non-local paths (GitHub Advisory, Fix Commit).
Successful exploitation allows an authenticated attacker to delete arbitrary files accessible to the DPanel process on the host server. This can result in system corruption, destruction of critical application or operating system files, and denial of service by removing essential DPanel or Docker daemon components. Because DPanel is typically deployed with access to the Docker socket and host filesystem volumes, the blast radius can extend beyond the container to the underlying host (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, demonstrating a simple POST request with a traversal payload (e.g., path=../../../../../../../../tmp/1.txt) to the /api/common/attach/delete endpoint using a valid Bearer token. Exploitation requires only low-privilege authenticated access to the DPanel administrative backend. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.108%, indicating low but non-zero probability of exploitation in the near term (GitHub Advisory).
http://target-ip:8807) and capture the Authorization: Bearer <token> JWT from the login response./etc/passwd, Docker daemon configuration, or DPanel service files)./dpanel/api/common/attach/delete with the path parameter set to a traversal sequence pointing to the target file, such as path=../../../../../../../../etc/passwd.POST /dpanel/api/common/attach/delete HTTP/1.1
Host: target-ip:8807
Authorization: Bearer <token>
Content-Type: application/x-www-form-urlencoded
path=../../../../../../../../etc/passwd/dpanel/api/common/attach/delete (or /api/common/attach/delete) containing ../ sequences or encoded traversal characters in the path parameter body; requests originating from unexpected IP addresses to DPanel's management port (default 8807).../ segments; HTTP 200 responses to delete requests targeting paths outside the expected storage directory./etc/, /var/, or other critical directories that should not be modified by the DPanel process.Upgrade DPanel to version 1.9.2 or later, which includes the fix for CVE-2025-66292 via the addition of filepath.IsLocal() validation and filepath.Clean() normalization before processing delete requests (DPanel v1.9.2 Release, Fix Commit). As interim mitigations, restrict access to the DPanel administrative backend to trusted IP addresses only using firewall rules or network-level controls, and apply the principle of least privilege to all accounts with DPanel administrative access. Avoid exposing the DPanel management port (default 8807) to untrusted networks.
The vulnerability was reported by security researcher pyroxenites and credited in the GitHub Security Advisory. Brief social media coverage appeared on Mastodon and Bluesky shortly after disclosure, and the CISA vulnerability bulletin for the week of January 12, 2026 referenced the CVE (GitHub Advisory). No significant vendor statements beyond the advisory or notable analyst commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."