HTB-Pterodactyl-RCE-CVE-2025-49132
Author
symphony2colour
Published
2026-02-09
Stars
1
Forks
0
Description
This repo contains RCE exploit for Pterodactyl htb machine
CVE-CVE-2025-49132 Details
Severity
CRITICAL
CVSS Score
10.0
CWE
CWE-94
Description
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issu...
Related PoCs for CVE-2025-49132
No other PoCs found for this CVE.