CVE-2025-49132General

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-08); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-24: 1Mentions · 2026-03-04: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-05-16: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-04: 1Technical Details · 2026-05-16: 102-0802-2403-0405-16
Signal classification2 categories
General
375.0%
Exploit
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-081
General1
2026-02-241
General1
2026-03-041
General1
2026-05-161
Exploit1
Full discourse4 posts
  • DFIR Radar@DFIR_Radar
    Exploit

    Critical directory traversal in Pterodactyl Panel v1.11.10 leads to unauthenticated RCE via PHP-PEAR exploitation chain. CVE-2025-49132 combines with PEAR pearcmd technique enabling arbitrary webshell deployment. Key technical details: • Endpoint /locales/locale.json bypasses auth middleware, accepts unsanitized locale/namespace parameters • Path traversal: locale=../../../../../usr/share/php/PEAR&namespace=pearcmd enables arbitrary .php file inclusion • PEAR pearcmd.php accepts config-create command via register_argc_argv, writes attacker-controlled content to disk • Payload: `<?=system($_REQUEST[0]);?>` creates webshell at /tmp/shell.php accessible via LFI Attack chain methodology: • Initial recon reveals Pterodactyl Panel v1.11.10 with PHP-PEAR enabled • Directory traversal to include pearcmd.php with malicious config creation • Second request includes written webshell for command execution • Database credential extraction leads to bcrypt hash cracking: !QAZ2wsx • Privilege escalation via CVE-2025-6018 (PAM environment bypass) + CVE-2025-6019 (libblockdev/udisks XFS mounting) Hunt for HTTP requests to `/locales/locale.json` with `../` sequences in locale parameter and suspicious namespace values targeting pearcmd.php. #DFIR_Radar

    Post summary

    The post outlines the exploitation chain for CVE-2025-49132 in Pterodactyl Panel, including detailed technical steps, PoC code, and potential escalation, but does not report active attacks or patches.

    110221.8K
    1.8K followersView on X
  • A. Kheiri@atkheiri
    General

    Solved Pyterodactyl (medium) Attack chain: → phpinfo.php exposure → CVE-2025-49132 (unauth RCE) → .env leak → DB creds → bcrypt hash crack → SSH One exposed file gave away the entire attack surface. Write-up on https://atank.vercel.app/writeups/hackthebox-pterodactyl-medium-experience. https://t.co/Bm8rPjRFk9

    Post summary

    The post details the use of CVE‑2025‑49132—an unauthenticated RCE—in a HackTheBox challenge, outlines the attack chain, and links to a write‑up for further reconstruction.

    00010120
    1 followersView on X
  • Brian_Bundi@bundibrianx
    General

    Just finished a deep dive into Pterodactyl on HackTheBox. This one was a beast—chaining CVE-2025-49132 for the initial foothold, then navigating PAM environment injection (CVE-2025-6018) and a UDisks2 LPE (CVE-2025-6019) to hit root. https://labs.hackthebox.com/achievement/machine/2252974/832 #HackTheBox #HTB

    Post summary

    A HackTheBox write‑up describes chaining three CVEs to reach root, providing only brief technical details but no PoC, exploit code, patches, or evidence of real‑world attacks.

    0001078
    2 followersView on X
  • s∅mdv3@JeffNjanja
    General

    PWN'D | HTB Season 10 — Pterodactyl Just rooted another HTB machine! 🎯 Chained CVE-2025-49132 (Unauthenticated RCE on Pterodactyl Panel) https://t.co/hSdz6baRll

    Post summary

    The tweet reports that CVE-2025-49132, an unauthenticated RCE in Pterodactyl Panel, was used to root a Hack The Box machine, but no PoC, exploit code, patch, or wild exploitation details are provided.

    0000054
    66 followersView on X

Explore more