UNKNOWN Go

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

GO-2026-6120 · CVE-2026-54593 · GHSA-8r6w-3qq5-4p4r

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted file.create permissions in github.com/pterodactyl/wings

Ready to move

Start Securing

Free, no credit card | First findings in minutes