fig. 01 — GHSA-j752-cjcj-w847, the advisory selected below
// advisories
GHSA-j752-cjcj-w847
CRITICALCVE-2025-30206
The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine.