blob: 4ed46b77d9b335e5ece0fc42a80984a8ab777be6 [file] [log] [blame]
id: GO-2025-3612
modules:
- module: github.com/donknap/dpanel
versions:
- fixed: 1.6.1
vulnerable_at: 1.6.0
summary: Dpanel's hard-coded JWT secret leads to remote code execution in github.com/donknap/dpanel
cves:
- CVE-2025-30206
ghsas:
- GHSA-j752-cjcj-w847
references:
- advisory: https://github.com/donknap/dpanel/security/advisories/GHSA-j752-cjcj-w847
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-30206
source:
id: GHSA-j752-cjcj-w847
created: 2025-04-16T11:09:43.786918-04:00
review_status: UNREVIEWED