1panel-dev
26 CVEs tracked since 2023. Since Jul 2023, none of them reached CISA KEV.
1panel-dev CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-07 | 5 | 0 |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 14 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | null or fewer | |
| 2026-08 | null or fewer | |
| 2026-09 | 7 | 0 |
Products
The products that kept showing up in 1panel-dev's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting 1panel-dev.
- CVE-2026-79919MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)6.3
- CVE-2026-79918MaxKB: Sandbox escape via unhooked fexecve6.3
- CVE-2026-77517MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base5.4
- CVE-2026-77521MaxKB: Prompt-injectable agent can lead to command execution10.0
- CVE-2026-77522MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)4.3
- CVE-2026-79917MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation6.5
- CVE-2026-77516MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path5.4
- CVE-2026-77523MaxKB: Cross-workspace model parameter form write7.4
- CVE-2026-77525MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id4.2
- CVE-2026-77518MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows5.0
- CVE-2026-79916MaxKB AWS Bedrock model credential injection leads to remote code execution9.1
- CVE-2026-77520MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application5.4
- CVE-2026-77519MaxKB: Expired application API keys remain usable on `/chat/api/mcp`5.4
- CVE-2026-76899CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`5.7
- CVE-2026-76902CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`5.0
The record
- Peak rank
- #69 in Apr 2026
- Busiest month shown
- Apr 2026, 14 CVEs
- Months with a KEV entry
- 0 since Jul 2023
- Monthly snapshots
- 3 since 2023