
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66507 is a CAPTCHA bypass vulnerability in the 1Panel authentication API (an open-source VPS control panel by Fit2Cloud) that allows unauthenticated attackers to disable CAPTCHA verification by manipulating a client-controlled boolean parameter. It affects all versions of 1Panel prior to v2.0.14 and was disclosed on December 8, 2025, by researcher aliyevmursal via the GitHub Security Advisory GHSA-qmg5-v42x-qqhq. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, 1Panel Security Advisory).
The root cause is that the /api/login endpoint accepted a boolean field ignoreCaptcha directly from the client request body and used it server-side to determine whether CAPTCHA validation should be performed, with no server-side validation, session binding, or privilege checks (CWE-602, CWE-807, CWE-290). The vulnerable backend logic was: if !req.IgnoreCaptcha { captcha.VerifyCode(...) } — meaning any unauthenticated attacker could simply include "ignoreCaptcha": true in the JSON request body to skip CAPTCHA entirely. There were no compensating controls such as MFA requirements, IP reputation checks, rate limiting, or prior session validation (1Panel Security Advisory, Github Advisory). The fix in v2.0.14 removed the ignoreCaptcha field from the login DTO entirely and replaced it with a server-side IP-tracking mechanism (IPTracker) that determines CAPTCHA necessity based on failed login attempts from a given IP (Patch Commit).
Successful exploitation allows an unauthenticated attacker to bypass CAPTCHA protections on the 1Panel login endpoint, enabling fully automated brute-force or credential-stuffing attacks against administrator accounts. Because 1Panel is a VPS control panel with broad server management capabilities (Docker, firewall, file management, SSH, databases), a successful account takeover could result in complete server compromise, data exfiltration, and lateral movement within hosted infrastructure. The CVSS assessment rates confidentiality impact as High, with no direct integrity or availability impact from the bypass itself — though downstream account takeover would affect all three (Github Advisory, 1Panel Security Advisory).
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is trivially exploitable — it requires only a single modified HTTP request parameter with no authentication or special tooling. The EPSS score is approximately 0.141% (34th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (Github Advisory).
needCaptcha field is absent or the panel version is below 2.0.14./api/login with the JSON body including "ignoreCaptcha": true alongside credential fields, e.g.:{
"name": "admin",
"password": "<candidate_password>",
"ignoreCaptcha": true,
"captcha": "",
"captchaID": "",
"language": "en"
}/api/login from a single IP or small IP range in a short time window; login requests containing "ignoreCaptcha": true in the JSON body; absence of CAPTCHA fields (captcha, captchaID) in login request payloads.ErrAuth) from the same source IP without CAPTCHA validation errors; successful login events following a large number of failed attempts from the same IP.Upgrade 1Panel to version v2.0.14 or later, which removes the client-controlled ignoreCaptcha parameter and replaces it with a server-side IP-based CAPTCHA enforcement mechanism (1Panel Release v2.0.14, Patch Commit). As interim mitigations for those unable to upgrade immediately: restrict access to the 1Panel web interface to trusted IP ranges via firewall rules, enable multi-factor authentication if available, and monitor authentication logs for anomalous login patterns. Implementing an external WAF or reverse proxy with rate limiting on the login endpoint can also reduce the risk of automated attacks (1Panel Security Advisory).
The vulnerability was reported by researcher aliyevmursal and disclosed responsibly through GitHub's security advisory process by the 1Panel maintainer wanghe-fit2cloud on December 8, 2025. The fix was included in the v2.0.14 release alongside a related X-Forwarded-For header bypass fix, suggesting a broader security review of the authentication subsystem. No significant broader media coverage or notable community controversy has been observed beyond the standard advisory publication (1Panel Security Advisory, 1Panel Release v2.0.14).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."