CVE-2025-49132

CRITICAL EXPLOITED NUCLEI

Pterodactyl Panel < 1.11.11 - Code Injection

Title source: rule

Description

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

Exploits (43)

exploitdb SCANNER
by Zen-kun04 · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52341
nomisec WORKING POC 18 stars
by YoyoChaud · remote
https://github.com/YoyoChaud/CVE-2025-49132
nomisec WORKING POC 16 stars
by Zen-kun04 · infoleak
https://github.com/Zen-kun04/CVE-2025-49132
nomisec WORKING POC 12 stars
by malw0re · poc
https://github.com/malw0re/CVE-2025-49132-Mods
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-49132
nomisec WORKING POC 5 stars
by 63square · remote
https://github.com/63square/CVE-2025-49132
nomisec WORKING POC 4 stars
by GRodolphe · remote
https://github.com/GRodolphe/CVE-2025-49132_poc
nomisec WORKING POC 4 stars
by qiaojojo · infoleak
https://github.com/qiaojojo/CVE-2025-49132_poc
nomisec WORKING POC 3 stars
by dollarboysushil · remote
https://github.com/dollarboysushil/CVE-2025-49132-Pterodactyl-Panel-Unauthenticated-Remote-Code-Execution-RCE-
nomisec WORKING POC 2 stars
by str1keboo · remote
https://github.com/str1keboo/CVE-2025-49132
nomisec WORKING POC 2 stars
by pxxdrobits · poc
https://github.com/pxxdrobits/CVE-2025-49132
nomisec WORKING POC 2 stars
by 0xtensho · poc
https://github.com/0xtensho/CVE-2025-49132-poc
nomisec WORKING POC 1 stars
by Ahmedf000 · remote
https://github.com/Ahmedf000/CVE-2025-49132_HTB_SEASON10
nomisec WORKING POC 1 stars
by rippsec · poc
https://github.com/rippsec/CVE-2025-49132-PHP-PEAR
nomisec WORKING POC 1 stars
by rippxsec · poc
https://github.com/rippxsec/CVE-2025-49132-PHP-PEAR
nomisec WORKING POC 1 stars
by Pwndalf · remote
https://github.com/Pwndalf/CVE-2025-49132-PoC
nomisec WORKING POC 1 stars
by ramzihafiz · remote
https://github.com/ramzihafiz/CVE-2025-49132
nomisec WRITEUP
by karimelsheikh1 · poc
https://github.com/karimelsheikh1/HTB-Pterodactyl-Writeup
nomisec WRITEUP
by V0idW1re · poc
https://github.com/V0idW1re/HTB-Pterodactyl-Writeup
nomisec WRITEUP
by V0idW1re · poc
https://github.com/V0idW1re/htb-pterodactyl-writeup
nomisec SCANNER
by unixskid · poc
https://github.com/unixskid/CVE-2025-49132
nomisec SCANNER
by revasec · poc
https://github.com/revasec/CVE-2025-49132
nomisec WORKING POC
by 4nuxd · remote
https://github.com/4nuxd/CVE-2025-49132
github WORKING POC
by Kl3lCrypt · pythonpoc
https://github.com/Kl3lCrypt/cve-exploits/tree/main/CVE-2025-49132
nomisec WORKING POC
by popyue · remote
https://github.com/popyue/CVE-2025-49132
nomisec WORKING POC
by nik123-py · poc
https://github.com/nik123-py/CVE-2025-49132_HTB_SEASON10
nomisec WORKING POC
by rippxsec · poc
https://github.com/rippxsec/CVE-2025-49132
nomisec WORKING POC
by rippsec · poc
https://github.com/rippsec/CVE-2025-49132
nomisec WORKING POC
by scroollocker · remote
https://github.com/scroollocker/CVE-2025-49132
nomisec WORKING POC
by thealchimist86 · remote
https://github.com/thealchimist86/CVE-2025-49132-Pterodactyl-Panel-RCE
nomisec WORKING POC
by matesz44 · remote
https://github.com/matesz44/CVE-2025-49132
nomisec WORKING POC
by kerburenthusiasm · remote
https://github.com/kerburenthusiasm/CVE-2025-49132-PoC
nomisec WORKING POC
by 0xf3d0rq · poc
https://github.com/0xf3d0rq/CVE-2025-49132
nomisec SCANNER
by WebSafety-2tina · remote
https://github.com/WebSafety-2tina/CVE-2025-49132
nomisec SCANNER
by melonlonmeo · infoleak
https://github.com/melonlonmeo/CVE-2025-49132
nomisec WORKING POC
by typicalsmc · poc
https://github.com/typicalsmc/CVE-2025-49132-PoC
vulncheck_xdb SUSPICIOUS
remote
https://github.com/adamshaikhma/CVE-2026-1844
vulncheck_xdb WORKING POC
remote
https://github.com/xffsec/CVE-2025-49132
vulncheck_xdb WORKING POC
remote
https://github.com/malw0re/CVE-2025-49132---Pterodactyl-RCE-HTB-Season-10-
vulncheck_xdb WORKING POC
remote
https://github.com/nfoltc/CVE-2025-49132

Nuclei Templates (1)

Pterodactyl Panel - Remote Code Execution
CRITICALVERIFIEDby darses
Shodan: title:"Pterodactyl" || http.favicon.hash:-456405319 || http.favicon.hash:846001371 || Set-Cookie: pterodactyl_session=
FOFA: title="Pterodactyl" || icon_hash="-456405319" || icon_hash="846001371" || Set-Cookie: pterodactyl_session=

Scores

CVSS v3 10.0
EPSS 0.1566
EPSS Percentile 94.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

VulnCheck KEV 2025-06-19
CWE
CWE-94
Status published
Products (2)
pterodactyl/panel 0 - 1.11.11Packagist
pterodactyl/panel < 1.11.11
Published Jun 20, 2025
Tracked Since Feb 18, 2026