Executive brief
OpenPanel is a hosting control panel API that provides web application management. The /misc/favicon and /misc/og endpoints allow unauthenticated attackers to make arbitrary HTTP requests to internal servers and cloud metadata services, potentially exposing sensitive credentials and internal service information. An attacker can retrieve internal resources and cloud IAM credentials without authentication.
Technical details
This is an unauthenticated server-side request forgery (SSRF) vulnerability in OpenPanel before 2.3.0. The /misc/favicon and /misc/og endpoints accept a user-supplied URL parameter with insufficient validation—only checking for http/https protocols but allowing access to private IP ranges and internal hostnames. The fetchImage() function follows redirects without filtering, allowing bypass of the image-extension check. Small responses (under 5 KB for /favicon, under 10 KB for /og) are returned verbatim to the attacker, enabling credential theft from cloud metadata endpoints and enumeration of internal services. No authentication is required; the endpoints are mounted without auth preHandlers.
Affected products
- OpenPanel OpenPanel before 2.3.0
Timeline
- 2026-08-20: disclosed: Security advisory published by OpenPanel
- 2026-09-04: patched: Fixed in version 2.3.0