Stored XSS Vulnerability in 1Panel Control Panel for Linux Servers
CVE-2026-23525

6.4MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 January 2026

What is CVE-2026-23525?

A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store, compromising the integrity of web application interactions. The issue arises when users view application details, as malicious scripts can execute within the user's browser context. This could lead to the theft of session cookies, unauthorized access to sensitive system functionalities, or other malicious actions that threaten the overall security. The underlying problem stems from inadequate content sanitization in the MdEditor component, specifically while using the previewOnly attribute. To address this critical issue, applying appropriate XSS protection and content sanitization mechanisms is essential, particularly in all rendering processes. Versions v1.10.34-lts and v2.0.17 have been patched to mitigate these vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

1Panel < 1.10.34 < 1.10.34

1Panel >= 2.0.0, < 2.0.17 < 2.0.0, 2.0.17

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.