CVE-2025-56413: FIT2CLOUD 1panel

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint.

Affected products

Published 2025-09-10. Last modified 2026-06-17.