Feed/CVE-2025-49132
CVE-2025-49132CRITICALCVSS 10.0

CVE-2025-49132

Published Jun 20, 2025·Updated Jun 17, 2026

NVD Description

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

Public Exploits & PoCs22 found

PoC: CVE-2025-49132

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

4

PoC: CVE-2025-49132

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

1

PoC: CVE-2025-49132

Check a list of Pterodactyl panels for vulnerabilities from a file.

1

PoC: CVE-2025-49132

Check a list of Pterodactyl panels for vulnerabilities from a file.

1

PoC: HTB-Pterodactyl-Writeup

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2 privilege escalation).

PoC: htb-pterodactyl-writeup

HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM pam_environment bypass) + CVE-2025-6019 (udisks2 XFS resize race condition, nosuid bypass) → root. Full notes and steps included.

PoC: CVE-2025-49132

The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.

PoC: CVE-2025-49132

CVE For Pterodactyl (For Study and Education)

PoC: CVE-2025-49132

CVE-2025-49132

PoC: CVE-2025-49132-Pterodactyl-Panel-RCE

Exploit CVE-2025-49132 Pterodactyl Panel RCE

PoC: CVE-2025-49132-Pterodactyl-Panel-Unauthenticated-Remote-Code-Execution-RCE-

PoC exploit for CVE-2025-49132 (GHSA-24wv-6c99-f843) – Unauthenticated Remote Code Execution in Pterodactyl Panel ≤ 1.11.10

PoC: CVE-2025-49132-PoC

This script exploits Remote Code Execution vulnerability in Pterodactyl Panel < 1.11.11

PoC: CVE-2025-49132

CVE-2025-49132: Pterodactyl Panel UnauthN LFI to RCE (w/ pearcmd) in posix sh

PoC: HTB-Pterodactyl-RCE-CVE-2025-49132

This repo contains RCE exploit for Pterodactyl htb machine

PoC: CVE-2025-49132

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

PoC: CVE-2025-49132

This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

PoC: CVE-2025-49132

CVE-2025-49132 is a critical arbitrary code execution vulnerability affecting the Pterodactyl game server management panel. This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected systems, potentially leading to full system compromise

PoC: CVE-2025-49132

CVE-2025-49132

PoC: CVE-2025-49132_poc

This is an improved version of the CVE-2025-49132 proof of concept exploit.

PoC: CVE-2025-49132

Scanner - CVE-2025-49132

PoC: CVE-2025-49132

PoCs for CVE-2025-49132

PoC: CVE-2025-49132_poc

Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free