Junglewise Threat Intelligence

CVE-2026-72573: 4xmen pm2panel OS command injection in process restart handler

CVE-2026-72573 · Severity: high · CVSS 8.8 · Published 2026-08-10

Executive brief

pm2panel is a web-based control panel for managing Node.js processes through a PM2 process manager. An authenticated attacker can inject arbitrary operating system commands through an unsanitized parameter, leading to complete compromise of the host system where the panel runs.

Technical details

The vulnerability is an OS command injection flaw in the pm2panel.js request handler. The application passes the unsanitized req.query.id parameter directly to an exec() call that executes 'pm2 restart ' + id without input validation or shell escaping. An authenticated remote attacker can exploit this by chaining shell commands via semicolons or other metacharacters in the id parameter, achieving arbitrary command execution with the privileges of the pm2panel process. The vulnerability affects all versions and requires prior authentication to the panel, though default credentials (admin/admin) are widely known.

Affected products

  • 4xmen pm2panel all versions

Timeline

  • 2026-08-10: disclosed
  • other: CVE-2026-72573 assigned

References