aaPanel through version 6.8.12 is vulnerable to Cross-Site WebSocket Hijacking (CSWH) in its WebSSH endpoint. The issue involves operating-system commands carried in WebSocket messages sent to the unencrypted WebSocket endpoint used for WebSSH. Exploitability is browser-dependent: Firefox is identified as exploitable, whereas Chrome is not.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains four files: two documentation files (README.md and ADVISORY.md) plus two Python scripts (check.py and exploit.py). The purpose of the repository is to document and demonstrate an aaPanel WebSocket vulnerability chain: Cross-Site WebSocket Hijacking against aaPanel WebSocket endpoints, bypass of the WebSocket CSRF protection, and remote command execution through /sock_shell. The exploit is not part of a larger framework. The main exploit logic is in exploit.py. It uses Python asyncio and the websockets library to connect to the target aaPanel instance at /sock_shell over ws:// or wss://, disables TLS certificate validation when using WSS, sends an initial JSON message containing an empty x-http-token field to attempt the CSRF bypass, then sends an arbitrary shell command and prints the returned output. The default payload is the shell command 'id', but the command is user-supplied, so the exploit supports arbitrary command execution if the target conditions are met. The repository also includes check.py, which is a detection script rather than an exploit. It iterates over multiple aaPanel WebSocket endpoints (/webssh, /sock_shell, /ws_panel, /ws_home, /ws_project, /ws_model, /workorder_client), attempts a WebSocket connection, sends the same empty-token probe, and classifies responses as protected, auth-required, or potentially vulnerable. This script does not execute commands. Documented capabilities include: establishing unauthenticated WebSocket upgrades prior to application-layer auth checks, probing multiple aaPanel WebSocket endpoints, bypassing CSRF checks under certain conditions, executing arbitrary shell commands via /sock_shell, and potentially leveraging /webssh as an SSH proxy using attacker-supplied credentials. The attack model is primarily web-based CSWSH requiring a logged-in aaPanel administrator, though the documentation also describes alternate API/AES bypass conditions. Overall, this is a real PoC/operational exploit repository with a companion scanner. It targets aaPanel Web Hosting Control Panel versions described in the docs as affected after the incomplete fix for CVE-2021-37840, and its primary impact is root-level remote code execution on the aaPanel host.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.