Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Modified: 2/3/2026
package
pkg:go/github.com/pterodactyl/wings
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Modified: 2/3/2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Modified: 8/18/2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
Modified: 2/23/2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered
Modified: 2/3/2026
Pterodactyl Wings vulnerable to improper isolation of server file access
Modified: 9/10/2026
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system
Modified: 2/4/2026
Unchecked hostname resolution could allow access to local network resources by users outside the local network
Modified: 2/4/2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
Modified: 2/3/2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Modified: 8/18/2026
Pterodactyl Wings vulnerable to Arbitrary File Write/Read
Modified: 9/10/2026
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Modified: 7/8/2026
Wings vulnerable to escape to host from installation container
Modified: 9/10/2026
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
Modified: 2/4/2026
Wings exposes node configuration secrets through egg configuration-file templating
Modified: 8/18/2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Modified: 8/18/2026
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull
Modified: 2/4/2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
Modified: 7/7/2026
Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/wings
Modified: 3/3/2026
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings
Modified: 3/3/2026
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings
Modified: 3/3/2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings
Modified: 2/23/2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings
Modified: 7/7/2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
Modified: 8/18/2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
Modified: 8/18/2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
Modified: 8/18/2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
Modified: 8/18/2026