{"id":"GHSA-8r6w-3qq5-4p4r","summary":"Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions","details":"### Summary\nA privilege escalation vulnerability exists in the Wings /upload/file endpoint due to insufficient validation of panel-signed JWTs. Wings accepts any valid panel-signed JWT containing `server_uuid`, `user_uuid`, and `unique_id`, regardless of the token’s intended purpose. Because the Panel issues JWTs with these same claims for other lower-privilege operations (such as WebSocket authentication and file download links), an authenticated subuser can reuse one of those tokens to upload arbitrary files without possessing the required `file.create` permission.\n\n### Impact\nAny subuser with permission to connect to a server's console, download files, or download backups could reuse those tokens to upload arbitrary files to the _same server_. A user that does not have access to a server as a subuser is not able to arbitrarily upload files.\n\n### Details\nThe panel generated JWT tokens for various purposes:\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Services/Backups/DownloadLinkService.php#L33-L36\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/FileUploadController.php#L45\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/WebsocketController.php#L58-L61\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/FileController.php#L82-L85\nThough as the actual purpose is not conveyed part of the JWT tokens, this introduces this vulnerability of being able to do non-intended actions due to the expected fields (i.e. `server_uuid`) on most endpoints being the same when parsing it on wings' side.  \n\n### PoC\nCreate a new subuser that has the minimal amount of permissions on a server (`websocket.connect`). As that subuser, retrieve a websocket JWT token from the `GET /api/client/servers/[...]/websocket` endpoint (in my case, I manually just make a request under that user's browser session; you can probably just resend the /websocket request in browser console to get a fresh unused token). Using that websocket token, we can abuse this by directly using it in the `/upload/file` endpoint of the wings node instead of using it for websocket authentication:\n```python3\nimport requests\n\nwings_url = 'http://[...]:8080'\nwebsocket_token = '[...]'\n\nres = requests.post(f'{wings_url}/upload/file', params = {\n    'token': websocket_token,\n}, files = {\n    'files': ('file-upload.txt', b'Hello, World!'),\n})\nprint(res.status_code, res.content)\n```\nObserve, that even though our subuser never has permissions outside viewing the console, they are able to write arbitrary files in the server. This pattern happens in a lot of other action, but this is probably the most interesting one.","aliases":["CVE-2026-54593","GO-2026-6120"],"modified":"2026-08-18T15:11:24.551383183Z","published":"2026-07-28T15:43:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-28T15:43:25Z","nvd_published_at":null,"cwe_ids":["CWE-1259","CWE-1270"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/pull/5636"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7"},{"type":"WEB","url":"https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c"},{"type":"PACKAGE","url":"https://github.com/pterodactyl/panel"}],"affected":[{"package":{"name":"pterodactyl/panel","ecosystem":"Packagist","purl":"pkg:composer/pterodactyl/panel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.3"}]}],"versions":["v0.1.0-beta","v0.1.1-beta","v0.1.2-beta","v0.2.0-beta","v0.3.0-beta","v0.4.0-beta","v0.4.1-beta","v0.5.0","v0.5.0-rc.1","v0.5.0-rc.2","v0.5.1","v0.5.2","v0.5.3","v0.5.4","v0.5.5","v0.5.6","v0.5.7","v0.6.0","v0.6.0-beta.1","v0.6.0-beta.2","v0.6.0-beta.2.1","v0.6.0-rc.1","v0.6.1","v0.6.2","v0.6.3","v0.6.4","v0.7.0","v0.7.0-beta.1","v0.7.0-beta.2","v0.7.0-beta.3","v0.7.0-beta.4","v0.7.0-rc.1","v0.7.0-rc.2","v0.7.1","v0.7.10","v0.7.11","v0.7.12","v0.7.13","v0.7.14","v0.7.15","v0.7.16","v0.7.17","v0.7.18","v0.7.19","v0.7.2","v0.7.3","v0.7.4","v0.7.5","v0.7.6","v0.7.7","v0.7.8","v0.7.9","v0.8.0-alpha.1","v0.8.0-alpha.2","v1.0.0","v1.0.0-beta.1","v1.0.0-beta.2","v1.0.0-beta.3","v1.0.0-beta.4","v1.0.0-beta.5","v1.0.0-beta.6","v1.0.0-beta.7","v1.0.0-rc.1","v1.0.0-rc.2","v1.0.0-rc.3","v1.0.0-rc.4","v1.0.0-rc.5","v1.0.0-rc.6","v1.0.0-rc.7","v1.0.1","v1.0.2","v1.0.3","v1.1.0","v1.1.1","v1.1.2","v1.1.3","v1.10.0","v1.10.1","v1.10.2","v1.10.3","v1.10.4","v1.11.0","v1.11.0-rc.1","v1.11.0-rc.2","v1.11.1","v1.11.10","v1.11.11","v1.11.2","v1.11.3","v1.11.4","v1.11.5","v1.11.6","v1.11.7","v1.11.8","v1.11.9","v1.12.0","v1.12.1","v1.12.2","v1.2.0","v1.2.1","v1.2.2","v1.3.0","v1.3.1","v1.3.2","v1.4.0","v1.4.1","v1.4.2","v1.5.0","v1.5.1","v1.6.0","v1.6.1","v1.6.2","v1.6.3","v1.6.5","v1.6.6","v1.7.0","v1.8.0","v1.8.1","v1.9.0","v1.9.1","v1.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8r6w-3qq5-4p4r/GHSA-8r6w-3qq5-4p4r.json"}},{"package":{"name":"github.com/pterodactyl/wings","ecosystem":"Go","purl":"pkg:golang/github.com/pterodactyl/wings"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8r6w-3qq5-4p4r/GHSA-8r6w-3qq5-4p4r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}