UNKNOWN Go
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
GO-2026-6120 · CVE-2026-54593 · GHSA-8r6w-3qq5-4p4r
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted file.create permissions in github.com/pterodactyl/wings
References
- ADVISORY https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r
- FIX https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c
- WEB https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7
- WEB https://github.com/pterodactyl/panel/pull/5636
Ready to move
Start Securing
Free, no credit card | First findings in minutes