ZPanel is a self-hosted panel that may run with access to private services, uploaded files, and optionally the host Docker socket. Please report security issues privately.
Security fixes target the latest published ZPanel release. If you are running an older release, upgrade before reporting an issue unless the issue still affects the latest version.
Please do not open a public GitHub issue for vulnerabilities.
Report privately through GitHub Security Advisories:
https://github.com/vivalucas/zpanel/security/advisories/new
Include:
- A clear description of the vulnerability
- Steps to reproduce
- Affected version or commit
- Deployment mode, such as Docker Compose or local binary
- Any relevant logs, screenshots, or proof-of-concept details
- Mounting
/var/run/docker.sockgives ZPanel administrative control over the host Docker daemon. - Custom CSS and JavaScript should only be enabled for trusted administrators.
- Public access mode should be reviewed before exposing a panel to the internet.