{"id":"CVE-2025-53363","aliases":["GHSA-gcqf-pxgg-gw8q","GO-2025-3909"],"url":"https://o3.security/vulnerability/CVE-2025-53363","summary":"Dpanel has an arbitrary file read vulnerability","details":"dpanel is an open source server management panel written in Go. In versions 1.2.0 through 1.7.2, dpanel allows authenticated users to read arbitrary files from the server via the /api/app/compose/get-from-uri API endpoint. The vulnerability exists in the GetFromUri function in app/application/http/controller/compose.go, where the uri parameter is passed directly to os.ReadFile without proper validation or access control. A logged-in attacker can exploit this flaw to read sensitive files from the host system, leading to information disclosure. No patched version is available as of this writing.","published":"2025-08-22T15:18:01.533Z","modified":"2026-07-15T01:49:20.736057090Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/donknap/dpanel","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53363.json"},{"type":"ADVISORY","url":"https://github.com/donknap/dpanel/security/advisories/GHSA-gcqf-pxgg-gw8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53363"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:20.736057090Z"}}