{"id":"CVE-2025-34430","aliases":["GHSA-5xpq-2vmc-5cqp","GO-2025-4230"],"url":"https://o3.security/vulnerability/CVE-2025-34430","summary":"1Panel CSRF Panel Name Modification","details":"1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a panel-name change request; if a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows a remote attacker to change the victim’s panel name to an arbitrary value without consent.","published":"2025-12-10T18:23:14.598Z","modified":"2026-07-31T18:31:45.770814960Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/1Panel-dev/1Panel","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://1panel.pro/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/34xxx/CVE-2025-34430.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-34430"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/1panel-csrf-panel-name-modification"},{"type":"PACKAGE","url":"https://github.com/1Panel-dev/1Panel"},{"type":"PACKAGE","url":"https://github.com/1Panel-dev/1Panel/releases"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-31T18:31:45.770814960Z"}}