SCA: security update for github.com/pterodactyl/wings, pterodactyl/panel (GHSA-8r6w-3qq5-4p4r)

high Tenable Self-Hosted Container Security Plugin ID 445402

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings
version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained
server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the
Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket
authentication and file-download links, an authenticated subuser could reuse one of those tokens (for
example a WebSocket token obtained with only the websocket.connect permission) by replaying it against
/upload/file to write arbitrary files to the same server, despite never being granted the file.create
permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2. (CVE-2026-54593)

Solution

Update the github.com/pterodactyl/wings library and its related packages to version 1.12.2 or later.

See Also

https://github.com/advisories/GHSA-8r6w-3qq5-4p4r

Plugin Details

Severity: High

ID: 445402

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/28/2026

Updated: 7/28/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2026-54593

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/28/2026

Vulnerability Publication Date: 7/28/2026

Reference Information

CVE: CVE-2026-54593