Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2025-52562 โ€” AI Deep Analysis Summary

CVSS 10.0 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Convoy Panel < 4.4.1 suffers from a **Directory Traversal** flaw in the `LocaleController`.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)**. The `LocaleController` fails to sanitize user input, allowing path manipulation to escape the intended directory structure.

Q3Who is affected? (Versions/Components)

๐Ÿ‘ฅ **Affected**: **Convoy Panel** versions **prior to 4.4.1**. Specifically targets the **LocaleController** component used by hosting providers and enthusiasts.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Capabilities**: With **High** impact (CVSS H/H/H), hackers can: ๐Ÿ”“ Access sensitive server files (configs, keys). ๐Ÿ’พ Modify application logic.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

โšก **Exploitation Threshold**: **LOW**. CVSS Vector `AV:N/AC:L/PR:N/UI:N` means: ๐ŸŒ Network accessible. ๐ŸŽฏ Low complexity. ๐Ÿ”‘ No authentication required. ๐Ÿ‘ค No user interaction needed. Easy to exploit!

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ“ฆ **Public Exploit**: **No**. The `pocs` field is empty. However, the vulnerability is confirmed via GitHub Advisory (GHSA-43g3-qpwq-hfgg). Wild exploitation is likely imminent given the low barrier.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for Convoy Panel instances. Check version numbers. Look for `LocaleController` endpoints in network traffic.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Official Fix**: **YES**. Patched in **Convoy Panel 4.4.1**. ๐Ÿ“ Commit: `f8d6202f3e4912b65dbd9f80ba625576944ab36c`. Update immediately to the latest version.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch Workaround**: If you cannot update: ๐Ÿšซ Restrict network access to the panel (Firewall/WAF). ๐Ÿ”’ Disable the `LocaleController` if possible. ๐Ÿ›‘ Monitor logs for unusual file access patterns.

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **CRITICAL**. CVSS Score is **High** (likely 9.8+). No auth required. Public advisory exists. **Action**: Patch NOW. Do not wait for an exploit to appear in the wild.