CVE-2025-66292: 
vulnerability analysis and mitigation

Overview

CVE-2025-66292 is an arbitrary file deletion vulnerability via path traversal in DPanel, an open-source Docker management panel written in Go. It affects all DPanel versions prior to 1.9.2 and was disclosed on January 15, 2026, via a GitHub Security Advisory. Authenticated users can exploit the /api/common/attach/delete interface to delete arbitrary files on the server by supplying path traversal sequences in the path parameter. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory).

Technical details

The root cause is improper path validation (CWE-22: Path Traversal; CWE-73: External Control of File Name or Path) in the Delete function within app/common/http/controller/attach.go. The user-supplied path parameter is passed directly to storage.Local{}.GetSaveRealPath() and subsequently to os.Remove() without sanitization or validation of traversal characters (../). The helper function in common/service/storage/local.go uses Go's filepath.Join, which resolves ../ sequences but does not enforce a chroot or jail boundary, allowing the resolved path to escape the intended storage directory. The fix in commit cbda0d9 adds a filepath.IsLocal() check and filepath.Clean() call before processing the path, rejecting any non-local paths (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an authenticated attacker to delete arbitrary files accessible to the DPanel process on the host server. This can result in system corruption, destruction of critical application or operating system files, and denial of service by removing essential DPanel or Docker daemon components. Because DPanel is typically deployed with access to the Docker socket and host filesystem volumes, the blast radius can extend beyond the container to the underlying host (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, demonstrating a simple POST request with a traversal payload (e.g., path=../../../../../../../../tmp/1.txt) to the /api/common/attach/delete endpoint using a valid Bearer token. Exploitation requires only low-privilege authenticated access to the DPanel administrative backend. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.108%, indicating low but non-zero probability of exploitation in the near term (GitHub Advisory).

Exploitation steps

  1. Obtain credentials: Acquire valid DPanel administrative credentials through phishing, credential stuffing, or other means, as the vulnerability requires authentication.
  2. Authenticate and retrieve token: Log in to the DPanel dashboard (e.g., http://target-ip:8807) and capture the Authorization: Bearer <token> JWT from the login response.
  3. Identify target file: Determine the path of a critical file to delete on the server (e.g., /etc/passwd, Docker daemon configuration, or DPanel service files).
  4. Craft traversal payload: Construct a POST request to /dpanel/api/common/attach/delete with the path parameter set to a traversal sequence pointing to the target file, such as path=../../../../../../../../etc/passwd.
  5. Send the request: Submit the request with the captured Bearer token:
POST /dpanel/api/common/attach/delete HTTP/1.1
Host: target-ip:8807
Authorization: Bearer <token>
Content-Type: application/x-www-form-urlencoded

path=../../../../../../../../etc/passwd
  1. Confirm deletion: Verify the file has been deleted by attempting to access it or observing service disruption on the target system (GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /dpanel/api/common/attach/delete (or /api/common/attach/delete) containing ../ sequences or encoded traversal characters in the path parameter body; requests originating from unexpected IP addresses to DPanel's management port (default 8807).
  • Logs: DPanel access logs showing repeated or anomalous calls to the attach delete endpoint with path values containing multiple ../ segments; HTTP 200 responses to delete requests targeting paths outside the expected storage directory.
  • File System: Unexpected disappearance of system files, configuration files, or DPanel/Docker service files; missing files in /etc/, /var/, or other critical directories that should not be modified by the DPanel process.
  • Process: DPanel or Docker daemon crashes or unexpected restarts following file deletion events, potentially indicating removal of essential runtime files (GitHub Advisory).

Mitigation and workarounds

Upgrade DPanel to version 1.9.2 or later, which includes the fix for CVE-2025-66292 via the addition of filepath.IsLocal() validation and filepath.Clean() normalization before processing delete requests (DPanel v1.9.2 Release, Fix Commit). As interim mitigations, restrict access to the DPanel administrative backend to trusted IP addresses only using firewall rules or network-level controls, and apply the principle of least privilege to all accounts with DPanel administrative access. Avoid exposing the DPanel management port (default 8807) to untrusted networks.

Community reactions

The vulnerability was reported by security researcher pyroxenites and credited in the GitHub Security Advisory. Brief social media coverage appeared on Mastodon and Bluesky shortly after disclosure, and the CISA vulnerability bulletin for the week of January 12, 2026 referenced the CVE (GitHub Advisory). No significant vendor statements beyond the advisory or notable analyst commentary have been identified.

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management