Intel

AIKIDO-2025-10485

panel is vulnerable to Missing Authentication for Critical Function

Missing Authentication for Critical Function Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 22, 2025

70

High Risk

This Affects:

Pythonpanel
1.5.0 - 1.7.3
Fixed in 1.7.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Authentication Bypass via unprotected static file endpoint due to improper access controls when serving static directories via the --static-dirs flag. Attackers can exploit this by accessing direct URLs without OAuth authentication, enabling unauthorized file downloads. It occurs because the static file endpoint lacks authentication checks, exposing all files in the designated directory to unauthenticated users.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

panel is vulnerable to Missing Authentication for Critical Function in versions 1.5.0 - 1.7.3.

How to fix this

Upgrade the panel library to the patch version.