An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.
[
{
"events": [
{
"introduced": "110.0.0"
},
{
"fixed": "126.0.37"
}
]
},
{
"events": [
{
"introduced": "128.0.1"
},
{
"fixed": "130.0.16"
}
]
},
{
"events": [
{
"introduced": "132.0.0"
},
{
"fixed": "132.0.4"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66429.json"