CVE-CVE-2025-49132
Severity
CRITICAL
CVSS Score
10.0
Description
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issu...
PoCs for CVE-CVE-2025-49132
HTB-Pterodactyl-RCE-CVE-2025-49132
RCE
Python
1
symphony2colour
2026-02-09