← Vulnerability feed

Vulnerability record · CVE-2023-25152 · published 8 February 2023

CVE-2023-25152: Pterodactyl wings link following vulnerability

Pterodactyl · Wings

Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine. In order to use this exploit, an attacker must have an existing "server" allocated and controlled by the Wings Daemon. This vulnerability has been resolved in version `v1.11.3` of the Wings Daemon, and has been back-ported to the 1.7 release series in `v1.7.3`. Anyone running `v1.11.x` should upgrade to `v1.11.3` and anyone running `v1.7.x` should upgrade to `v1.7.3`. There are no known workarounds for this vulnerability. ### Workarounds None at this time.

8.8 CVSS 3.1 High EPSS 0.68% · top 49.5% CWE-59 · Link following
8.8CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine. In order to use this exploit, an attacker must have an existing "server" allocated and controlled by the Wings Daemon. This vulnerability has been resolved in version `v1.11.3` of the Wings Daemon, and has been back-ported to the 1.7 release series in `v1.7.3`. Anyone running `v1.11.x` should upgrade to `v1.11.3` and anyone running `v1.7.x` should upgrade to `v1.7.3`. There are no known workarounds for this vulnerability. ### Workarounds None at this time.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25152 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-32080Pterodactyl wings execution with unnecessary privileges vulnerabilityWings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impact…EPSS 0.92%8.5CVE-2024-27102Pterodactyl wings path traversal vulnerabilityWings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability …EPSS 0.55%8.4CVE-2024-34066Pterodactyl wings vulnerabilityPterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting…EPSS 0.54%8.3CVE-2026-21696Pterodactyl wings uncontrolled resource consumption vulnerabilityWings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1…EPSS 0.54%8.3CVE-2025-69199Pterodactyl wings uncontrolled resource consumption vulnerabilityWings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings…EPSS 0.29%8.2CVE-2023-25168Pterodactyl wings link following vulnerabilityWings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vuln…EPSS 0.96%7.5CVE-2025-68954Pterodactyl panel insufficient session expiration vulnerabilityPterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is remo…EPSS 0.25%6.5CVE-2021-32699Pterodactyl wings uncontrolled resource consumption vulnerabilityWings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vu…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2023-25152), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.