CVE-2025-56413: OS Command Injection
OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56413?
CVE-2025-56413 is classified as a critical severity vulnerability due to its potential to allow attackers to execute arbitrary commands.
How do I fix CVE-2025-56413?
To fix CVE-2025-56413, update to the patched version of 1panel that addresses this OS command injection vulnerability.
What does CVE-2025-56413 affect?
CVE-2025-56413 specifically affects version 2.0.8 of the 1panel software.
What type of vulnerability is CVE-2025-56413?
CVE-2025-56413 is an OS command injection vulnerability that can be exploited via the operation parameter in a specific API endpoint.
Who can exploit CVE-2025-56413?
Any authenticated user can exploit CVE-2025-56413 due to insufficient input validation in the affected function.