Packagist (Composer) package
pterodactyl/panel
pkg:composer/pterodactyl/panel
Vulnerabilities (11)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-26016 | — | < 1.12.1 | 1.12.1 | Feb 19, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterod | ||
| CVE-2025-69198 | — | < 1.12.0 | 1.12.0 | Jan 19, 2026 | Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per | ||
| CVE-2025-69197 | — | < 1.12.0 | 1.12.0 | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in | ||
| CVE-2025-68954 | — | < 1.12.0 | 1.12.0 | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was alre | ||
| CVE-2025-49132 | Cri | 10.0 | < 1.11.11 | 1.11.11 | Jun 20, 2025 | Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute a | |
| CVE-2024-49762 | Med | 4.6 | < 1.11.8 | 1.11.8 | Oct 24, 2024 | Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted when using TLS, many webservers ( | |
| CVE-2024-34067 | — | < 1.11.6 | 1.11.6 | May 3, 2024 | Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. S | ||
| CVE-2021-41273 | — | < 1.6.6 | 1.6.6 | Nov 17, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node | ||
| CVE-2021-41176 | — | >= 1.0.0, < 1.6.3 | 1.6.3 | Oct 25, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This re | ||
| CVE-2021-41129 | — | >= 1.0.0, < 1.6.2 | 1.6.2 | Oct 6, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In r | ||
| CVE-2019-1020002 | — | < 0.7.14 | 0.7.14 | Jul 29, 2019 | Pterodactyl before 0.7.14 with 2FA allows credential sniffing. |
- CVE-2026-26016Feb 19, 2026affected < 1.12.1fixed 1.12.1
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterod
- CVE-2025-69198Jan 19, 2026affected < 1.12.0fixed 1.12.0
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per
- CVE-2025-69197Jan 6, 2026affected < 1.12.0fixed 1.12.0
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in
- CVE-2025-68954Jan 6, 2026affected < 1.12.0fixed 1.12.0
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was alre
- affected < 1.11.11fixed 1.11.11
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute a
- affected < 1.11.8fixed 1.11.8
Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted when using TLS, many webservers (
- CVE-2024-34067May 3, 2024affected < 1.11.6fixed 1.11.6
Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. S
- CVE-2021-41273Nov 17, 2021affected < 1.6.6fixed 1.6.6
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node
- CVE-2021-41176Oct 25, 2021affected >= 1.0.0, < 1.6.3fixed 1.6.3
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This re
- CVE-2021-41129Oct 6, 2021affected >= 1.0.0, < 1.6.2fixed 1.6.2
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In r
- CVE-2019-1020002Jul 29, 2019affected < 0.7.14fixed 0.7.14
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.