天下漏洞,尽知其名
CRITICAL

CVE-2026-101008 aaPanel BaoTa 命令注入漏洞

影响攻击者可远程执行任意命令,完全控制服务器

AI 研判

aaPanel(宝塔面板)11.8.0 及之前版本的文件合并处理组件存在命令注入漏洞。files.py 中 merge_split_file 函数未对 split_file_path 参数做安全过滤,导致攻击者可注入并执行系统命令。该漏洞利用方式已公开,且厂商未作回应。

影响范围

aaPanel BaoTa

aaPanel BaoTa 11.8.0 及更早版本(依据描述中的 up to 11.8.0),具体受影响版本范围暂无更详细的公开信息。

漏洞详情

漏洞位于 /www/server/panel/class/files.py 的 merge_split_file 函数,属于命令注入类型。该函数在处理文件合并时,将用户可控的 split_file_path 参数直接拼接到系统命令中执行,未进行充分校验或转义。远程攻击者可通过构造恶意参数注入任意系统命令,从而在服务器上执行。

利用条件与风险

攻击可远程发起,无需认证或仅需较低权限(具体前提暂无公开信息),且利用代码已公开,实战中被主动利用的风险很高。

修复建议

建议关注 aaPanel 官方更新,升级到修复该漏洞的版本;在官方补丁发布前,可限制面板访问来源、避免暴露到公网,并对 split_file_path 参数进行严格过滤作为临时缓解。厂商暂未回应,暂无官方修复方案公开信息。

原始情报

A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.