SCA: security update for github.com/tnborg/panel (GHSA-fm3m-jrgm-5ppg)

high Tenable Self-Hosted Container Security Plugin ID 428732

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an
attacker obtains the backend login path of RatPanel (including but not limited to weak default paths,
brute-force cracking, etc.), they can execute system commands or take over hosts managed by the panel
without logging in. In addition to this remote code execution (RCE) vulnerability, the flawed code also
leads to unauthorized access. RatPanel uses the CleanPath middleware provided by github.com/go-chi/chi
package to clean URLs, but but the middleware does not process r.URL.Path, which can cause the paths to be
misinterpreted. This is fixed in version 2.5.6. (CVE-2025-53534)

See Also

https://github.com/advisories/GHSA-fm3m-jrgm-5ppg

Plugin Details

Severity: High

ID: 428732

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 8/5/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.49

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2025-53534

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.7

Threat Score: 5.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/4/2025

Vulnerability Publication Date: 8/4/2025

Reference Information

CVE: CVE-2025-53534