Untriaged
Permalink
CVE-2026-52855
9.9 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Wings exposes node configuration secrets through egg configuration-file templating
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
References
-
https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6 x_refsource_CONFIRM
-
https://github.com/pterodactyl/wings/releases/tag/v1.12.3 x_refsource_MISC
Affected products
wings
- ==< 1.12.3
Matching in nixpkgs
pkgs.wings
Subdivision modeler inspired by Nendo and Mirai from Izware
pkgs.swingsane
Java GUI for SANE scanner servers (saned)
pkgs.python313Packages.pycarwings2
Python library for interacting with the NissanConnect EV
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>