Affected by GO-2024-2531
and 10 other vulnerabilities
GO-2024-2531: 1Panel set-cookie is missing the Secure keyword in github.com/1Panel-dev/1Panel
GO-2024-2613: Unauthorized Console access in github.com/1Panel-dev/1Panel
GO-2024-2636: 1Panel is vulnerable to command injection in github.com/1Panel-dev/1Panel
GO-2024-2734: 1Panel's password verification is suspected to have a timing attack vulnerability in github.com/1Panel-dev/1Panel
GO-2024-2990: 1Panel has an SQL injection issue related to the orderBy clause in github.com/1Panel-dev/1Panel
GO-2024-2992: 1Panel SQL injection in github.com/1Panel-dev/1Panel
GO-2025-4207: 1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers in github.com/1Panel-dev/1Panel
GO-2025-4209: 1Panel – CAPTCHA Bypass via Client-Controlled Flag in github.com/1Panel-dev/1Panel
GO-2025-4229: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality in github.com/1Panel-dev/1Panel
GO-2025-4230: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality in github.com/1Panel-dev/1Panel
GO-2025-4231: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality in github.com/1Panel-dev/1Panel