天下漏洞,尽知其名
HIGH

CVE-2026-101009 aaPanel BaoTa 命令注入漏洞

影响攻击者可远程执行任意系统命令

AI 研判

aaPanel(宝塔面板)的 panelTask.py 中 bt_task._unzip 函数在处理解压任务的 Password 参数时未做安全过滤,导致操作系统命令注入。该漏洞 CVSS 评分为 8.4,且利用方式已被公开披露,厂商未作回应。

影响范围

aaPanel BaoTa

aaPanel BaoTa 11.8.0 及以下版本(依据描述中的 up to 11.8.0),具体受影响范围暂无更详细的官方信息。

漏洞详情

漏洞位于 /www/server/panel/class/panelTask.py 的 bt_task._unzip 函数,属于解压处理组件。当解压任务传入的 Password 参数被攻击者控制时,程序未对特殊字符进行转义或过滤,直接拼接进系统命令执行,从而形成命令注入。攻击者可借助该参数注入任意 shell 命令,实现远程命令执行。

利用条件与风险

攻击者可远程发起利用,无需本地访问;由于利用代码已公开,实战中被扫描和攻击的风险较高。具体是否需要认证或特定接口权限,暂无公开信息。

修复建议

官方尚未发布修复版本或回应,建议关注 aaPanel 官方更新;临时缓解措施包括限制面板访问来源、避免使用带密码的解压功能,并对相关接口进行访问控制,具体方案以官方公告为准。

原始情报

A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.