CVE-2025-49132 is an unauthenticated arbitrary code execution vulnerability in Pterodactyl Panel affecting versions prior to 1.11.11. The issue is reachable via the /locales/locale.json endpoint when attacker-controlled locale and namespace query parameters are supplied. According to the provided content, a malicious actor can exploit this request path without authentication to achieve arbitrary code execution on the server hosting the Panel. Successful exploitation can expose the Panel host and its application environment, including configuration secrets, database-resident data, and files associated with servers managed through the panel.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
29 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (12 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-49132 affecting Pterodactyl Panel versions prior to 1.11.11. The repository contains only two files: a Python script (CVE-2025-49132_PoC.py) and a README. The script is the sole code artifact and serves as the entry point. The exploit capability is credential disclosure via an unauthenticated web request. It sends a GET request to the target's /locales/locale.json endpoint with crafted locale and namespace parameters: locale=../../../pterodactyl and namespace=config/database. If the target is vulnerable, the endpoint returns JSON exposing configuration data from the Pterodactyl application, and the script parses out MySQL connection details including host, port, database, username, and password. It then prints the credentials in connection-string form. Structurally, the script is simple: it parses a single target URL argument, normalizes the trailing slash, performs one HTTP request with redirects enabled and TLS verification disabled, checks for a 200 response containing the string 'pterodactyl', attempts JSON parsing, and reports either extracted credentials, a vulnerable-but-no-database condition, or not vulnerable / request error states. There is no shell payload, persistence, lateral movement, or automated post-exploitation logic in code. The README expands on the vulnerability and describes manual follow-on abuse, such as using disclosed database credentials to access the backend database and create an administrator account in the users table. However, those steps are not implemented in the script itself. Overall, this is an operational but basic exploit focused on unauthenticated sensitive configuration disclosure against a web-exposed Pterodactyl Panel endpoint.
This repository is a small standalone proof-of-concept exploit for CVE-2025-49132 affecting Pterodactyl Panel versions prior to 1.11.11. It contains two files: a Python exploit script and a README describing the vulnerability and post-exploitation ideas. The main script, CVE-2025-49132_PoC.py, is the entry point and uses requests, argparse, colorama, and urllib3. It accepts a single target URL, normalizes the trailing slash, disables TLS verification warnings, and sends one unauthenticated GET request to the vulnerable endpoint /locales/locale.json with locale=../../../pterodactyl and namespace=config/database. If the response is HTTP 200 and contains the string 'pterodactyl', it parses the returned JSON and extracts MySQL connection details from the exposed configuration structure, then prints them in host:port/database and username:password form. Error handling is basic and covers invalid JSON, missing expected keys, and request failures. The exploit’s core capability is sensitive configuration disclosure, specifically theft of database credentials, rather than direct code execution within the script itself. However, the README claims the underlying vulnerability can enable arbitrary code execution and describes follow-on abuse such as database access, account creation in the users table, and eventual administrative access to the panel. Overall, this is an operational web exploit PoC with a hardcoded request path and extraction logic focused on credential disclosure from vulnerable Pterodactyl installations.
This repository is a small, focused exploit PoC consisting of a README and a single Python script, pterodactyl_rce.py. It targets CVE-2025-49132 in Pterodactyl Panel versions prior to 1.11.11 and is clearly intended as an exploitation script rather than a detector. The code is standalone Python using only standard-library modules for HTTP serving, raw HTTP requests, threading, subprocess execution, and cleanup. The exploit flow is straightforward and operational: it accepts an attacker callback IP and port, generates a linux/x64/shell_reverse_tcp ELF with msfvenom, starts a one-shot HTTP server on port 8080 to host that ELF, then sends a crafted GET request to the vulnerable /locales/locale.json endpoint on the hardcoded host panel.pterodactyl.htb. The request abuses locale path traversal to reach ../../../../../usr/share/php/PEAR and uses namespace to invoke a PEAR config-create primitive that writes a PHP stager into /tmp/<random>.php. That stager runs system() with a command sequence that uses curl to download the hosted ELF into /tmp, chmods it, and executes it. A second crafted request to /locales/locale.json with locale=../../../../../tmp and namespace=<random_shell_name> triggers the staged PHP file. Optionally, the script starts nc -lvnp on the chosen port to catch the reverse shell, then deletes the local generated ELF. Notable characteristics: the target host is hardcoded; the exploit assumes HTTP on port 80; it depends on PHP-PEAR being installed in a specific path; and it requires outbound connectivity from the target to the attacker on TCP 8080 and the reverse-shell callback port. The repository structure is minimal and purpose-built for exploitation in a lab/HTB-style environment, with the README documenting prerequisites, usage, and defensive notes.
This repository is a small standalone exploit repo containing a README and one Python exploit script, poc.py. It targets CVE-2025-49132 in Pterodactyl Panel versions prior to 1.11.11. The exploit abuses an unauthenticated web endpoint, /locales/locale.json, to perform path traversal into a PEAR installation and invoke pearcmd.php with config-create so that attacker-controlled PHP code is written to disk. A second request then traverses to the written file and includes it for execution, yielding remote command execution. The Python script is an operational PoC rather than a simple detector. Based on the visible code and README, it provides multiple modes: direct command execution, reverse shell generation, interactive pseudo-shell behavior, PEAR path fuzzing, and a scan mode for checking vulnerability/config leakage. It uses Python requests/urllib3 networking, argparse for CLI handling, and includes retry/session handling and user-facing output helpers. The exploit is network/web-based and unauthenticated. Fingerprintable targets and artifacts in the repo center on the vulnerable endpoint and filesystem paths: /locales/locale.json, PEAR paths such as /usr/share/php/PEAR or user-supplied alternatives like /opt/pear, the PEAR handler pearcmd.php, and temporary payload locations such as /tmp/payload.php. The README explicitly documents the two-stage HTTP GET flow and notes that raw PHP metacharacters must remain unencoded for successful exploitation. Overall, the repository’s purpose is to provide a practical PoC for exploiting unauthenticated RCE in vulnerable Pterodactyl Panel deployments, with enough functionality to move beyond verification into actual command execution and reverse-shell access.
Repository purpose: a Python proof-of-concept exploit for CVE-2025-49132, described as an unauthenticated RCE in Pterodactyl Panel (< 1.11.11) by abusing the /locales/locale.json endpoint with path traversal to reach PHP PEAR’s pearcmd.php and using the '+config-create' command to write a malicious PHP file, then including it to execute commands. Structure: - README.md: Detailed vulnerability write-up, HTTP request examples for the two-stage attack (write payload to /tmp then execute), notes about URL encoding breaking the exploit, mitigation guidance, and references. - poc.py: Main exploit tool (Python 3) implementing multiple operator modes via argparse. Based on visible code and README, it: - Builds HTTP(S) requests to the target base URL derived from --host. - Supports single command execution (-c/--command). - Generates a reverse shell one-liner (-r/--reverse-shell LHOST:LPORT) and triggers it on the target. - Provides an interactive pseudo-shell (--shell) that repeatedly executes commands. - Includes --scan mode to check for vulnerability indicators (described as config leaks). - Includes --fuzz mode to probe for likely PEAR installation paths and suggests using a discovered path with -p/--pear-path. Exploit mechanics (as documented): 1) Stage 1 (write): GET /locales/locale.json with parameters crafted to invoke PEAR '+config-create' while traversing locale to the PEAR directory (e.g., ../../../../../../usr/share/php/PEAR) and embedding PHP code that calls system('<cmd>') into a file written to /tmp/payload.php. 2) Stage 2 (execute): GET /locales/locale.json traversing locale to /tmp and setting namespace to the payload name to include/execute the dropped PHP file. Notable operational detail: the README emphasizes that URL-encoding special characters in the injected PHP (e.g., <?= ... ?>) can prevent execution, implying the exploit must preserve raw characters in the query string.
Repository contains a PoC exploit for CVE-2025-49132 (unauthenticated RCE) in Pterodactyl Panel versions < 1.11.11. Structure is minimal: README.md (detailed write-up, HTTP request examples, and mitigation notes) and a single Python exploit script (poc.py). Core technique: the exploit abuses the unauthenticated /locales/locale.json endpoint with a path traversal in the 'locale' parameter to reach a PEAR installation directory and invoke PEAR’s pearcmd.php using the '+config-create' command. This allows writing an attacker-controlled PHP file (example: /tmp/payload.php) containing PHP code that executes system commands. A second request traverses to /tmp and includes the dropped file via the same endpoint (namespace=payload), resulting in command execution. poc.py implements multiple operator modes: (1) single command execution (-c), (2) reverse shell generation/execution (-r LHOST:LPORT), (3) interactive pseudo-shell (--shell), (4) fuzzing for likely PEAR installation paths (--fuzz), and (5) scanning (--scan) to identify vulnerable behavior/config leaks. It uses Python requests/urllib3 with SSL verification disabled warnings suppressed (intended for testing), and provides verbose/compact output plus a spinner for UX. No evidence of unrelated destructive behavior; functionality aligns with the described vulnerability and exploitation flow.
Repository contains a single Python script (CVE-2025-49132.py) and a README. Despite the README claiming unauthenticated RCE, the implemented code functions as a mass network scanner/extractor that abuses a locales JSON endpoint to retrieve configuration data. The script reads a list of target URLs from a file, normalizes them (adds http:// if missing), and concurrently scans them using a ThreadPoolExecutor. Core behavior: for each target it requests {target}/locales/locale.json with parameters locale=../../../pterodactyl and namespace=config/database, then validates the JSON structure and extracts database.connections.mysql fields (host, port, database, username, password). Successful hits are printed and appended to credentials.txt under a thread lock. It disables TLS verification warnings and sets verify=False, and includes basic error handling (timeouts, connection errors, SSL errors with a retry from https to http). Notable observables: the primary fingerprintable endpoint is /locales/locale.json and the key exploit parameters are locale=../../../pterodactyl and namespace=config/database (README lists additional namespaces like config/app, config/auth, config/session). Output artifacts include credentials.txt (used) and hit.txt (created but not used). Overall purpose is credential harvesting/config disclosure at scale rather than delivering a code-execution payload.
Repository contains a single Python PoC (poc.py) and a README. The PoC performs unauthenticated network exploitation against a Pterodactyl Panel endpoint /locales/locale.json by abusing the locale and namespace query parameters to achieve path traversal and write a PHP payload to /tmp/payload.php (Step 1), then trigger it by loading the payload namespace from /tmp (Step 2). The script uses os.system to run curl commands and sets a hardcoded Host header (panel.pterodactyl.htb), indicating reliance on a specific virtual host configuration. User-controlled input is --target (host) and --cmd (arbitrary command); the command is lightly obfuscated by replacing spaces with an IFS-based sequence before embedding into a PHP system() call. Overall purpose: provide a working RCE exploit chain (file write + execution) rather than mere detection.
Repository purpose: a standalone Python exploit for CVE-2025-49132 in Pterodactyl Panel, abusing an unauthenticated LFI in /locales/locale.json (locale + namespace parameters) to (1) read Laravel/PHP configuration files and (2) escalate to RCE by including PEAR's pearcmd.php and using its 'config-create' functionality to write a PHP webshell, then including that shell via the same LFI to execute commands. Structure: - exploit.py: main exploit implementation. Defines PterodactylExploit with a fixed target endpoint (TARGET/locales/locale.json) and uses requests.Session. Provides LFI read functionality that requests JSON and pretty-prints nested config values with highlighting for sensitive keys. Also contains RCE helpers (per README and CLI options) for interactive shell and single-command execution, writing a shell to a chosen directory/name. - README.md: detailed usage for --read and --rce modes, common PEAR paths, and explains the two-stage LFI->pearcmd->webshell chain. - requirements.txt: only requests. Exploit capabilities: - Unauthenticated LFI to read arbitrary includable PHP config arrays (database/app/etc.), enabling credential/APP_KEY disclosure. - LFI-to-RCE via pearcmd.php: writes a PHP webshell (default under /tmp) and executes arbitrary OS commands; supports one-shot command execution (--cmd) and an interactive loop; operator can supply reverse-shell commands. Notable observables: - Network target is the HTTP(S) endpoint /locales/locale.json on the victim. - File targets include traversal to config/*.php and PEAR installation paths (e.g., /usr/share/php/PEAR/pearcmd.php) and a dropped shell in /tmp.
Repository contains a Python exploit (ape1.py) and a README describing an unauthenticated RCE chain for CVE-2025-49132 affecting Pterodactyl Panel (<1.11.11). The exploit targets the /locales/locale.json endpoint, abusing locale and namespace query parameters to achieve LFI into a PEAR installation (pearcmd). It then uses pearcmd's config-create functionality to write a persistent PHP webshell to /tmp/shell.php containing system('<cmd>') with a space-bypass transformation (${IFS}). After writing, it triggers execution by requesting /locales/locale.json?locale=../../../../../tmp&namespace=shell, which causes the application to load the dropped shell and execute the supplied command. The script supports: (1) single-command execution, (2) an interactive shell loop, and (3) a PEAR path discovery mode that tests several common filesystem locations via traversal. Output handling includes basic parsing/cleaning to extract common indicators (uid=, HTB{flag}, passwd lines, ls output). Network interaction is performed via local curl subprocess calls; no embedded C2 endpoints are hardcoded beyond the target host/port and the fixed vulnerable paths.
Repository contains a Python proof-of-concept exploit for CVE-2025-49132 (unauthenticated RCE) affecting Pterodactyl Panel versions prior to 1.11.11. Structure is minimal: a detailed README describing the vulnerability and exploit flow, and a single exploit script `poc.py`. Core technique: the exploit abuses the Pterodactyl endpoint `/locales/locale.json` which accepts user-controlled `locale` and `namespace` parameters. By using path traversal in `locale`, the attacker reaches a PEAR installation directory and targets PEAR’s `pearcmd.php`. The script leverages PEAR’s `+config-create` command to write an arbitrary PHP file (payload) to disk (commonly `/tmp/payload.php`). A second request then traverses to `/tmp` and includes the dropped file (via `namespace=payload`), executing attacker-supplied OS commands through PHP (e.g., `system()`). Exploit capabilities implemented in `poc.py` (as indicated by the visible argument parser and main flow): - Single command execution (`--command/-c`). - Reverse shell helper (`--reverse-shell/-r`), generating a one-liner command and reminding the operator to run a listener. - Interactive pseudo-shell mode (`--shell`). - Fuzzing for PEAR installation paths (`--fuzz`) to find viable PEAR directories on the target. - Scan mode (`--scan`) to check for vulnerability indicators (described as config leaks). Operational notes from README: the exploit is sensitive to URL encoding; it requires special characters in the injected PHP payload (e.g., `<?=...?>`) to be sent unencoded so PEAR writes executable PHP rather than literal text. No hardcoded C2 infrastructure is present; the only network target is the user-supplied host, and the only fixed application endpoint is `/locales/locale.json`. The exploit is best categorized as OPERATIONAL (it provides multiple modes including reverse shell generation and path fuzzing, but is not part of a larger exploitation framework).
Repository contains a single Python exploit script (CVE-2025-49132.py) and a README. The exploit is an unauthenticated network RCE against a Pterodactyl Panel endpoint (/locales/locale.json) by abusing the locale and namespace query parameters. Structure/purpose: - CVE-2025-49132.py: CLI tool that takes --target and --cmd (optional --path for PEAR). It builds a PHP one-liner payload (system('<cmd>')) with basic space obfuscation using ${IFS}. It then performs two curl requests via os.system: 1) "Write" stage: crafts a request using a traversal to the PEAR path and a pearcmd/config-create style primitive to drop /tmp/payload.php containing the PHP system() call. 2) "Trigger" stage: requests /locales/locale.json again with locale traversing to /tmp and namespace=payload to execute the dropped PHP. - readme.md: describes impact (arbitrary code execution without authentication) and gives an example command that downloads and executes a shell script via curl|sh. Notable operational details: - Uses a hardcoded Host header (panel.pterodactyl.htb), implying the target may require a specific virtual host. - No vulnerability check; it directly attempts exploitation. - Payload is arbitrary command execution; post-exploitation actions are left to the operator (e.g., credential theft from .env, DB access, file access).
Repository contains a Python proof-of-concept exploit for CVE-2025-49132 targeting Pterodactyl Panel via the locales endpoint. Structure: (1) README.md describing the CVE at a high level and showing CLI usage; (2) exploit.py implementing the attack. exploit.py is a network RCE tool that uses curl (via subprocess) to send crafted requests to `/locales/locale.json`. It optionally auto-discovers a PEAR path by trying several directory-traversal-style candidate paths and requesting `namespace=pearcmd`. Once a path is selected, it crafts a `config-create` style request that attempts to write a PHP file into `/tmp/<random>.php` containing `system('<cmd>')` (spaces obfuscated as `${IFS}`), then triggers execution by requesting locale from `../../../../../tmp` with `namespace=<random>`. Output is parsed with a regex to extract command results. Notable implementation details: relies on external `curl` binary; drops a temporary PHP payload in /tmp; uses random 6-letter namespace/filename; provides `--target`, `--cmd`, and optional `--pear` arguments.
Repository contains a single Python PoC exploit (exploit.py) and a README describing CVE-2025-49132 affecting Pterodactyl Panel versions < 1.11.11. Core behavior (exploit.py): - Accepts target domain, attacker listener IP/port, and an optional PEAR path (default /usr/share/php/PEAR/). - Builds a bash reverse shell command and base64-encodes it. - Wraps the base64 blob in a command that decodes and pipes to bash using ${IFS} to avoid space filtering. - Sends two unauthenticated HTTP GET requests using pycurl: 1) A crafted request to /locales/locale.json with parameters suggesting a config creation/write primitive ("+config-create+/") combined with directory traversal into the PEAR path and a "pearcmd" namespace, embedding PHP code (<?=system('...')?>) and specifying an output path of /tmp/payload.php. 2) A second request to /locales/locale.json that traverses to /tmp and uses namespace=payload to load/execute the dropped PHP, resulting in command execution and a reverse shell back to the provided listener. Overall purpose: achieve remote code execution on vulnerable Pterodactyl Panel instances by writing and then triggering a PHP payload via a locale/config handling endpoint.
Repository contains a small, operational unauthenticated RCE exploit chain for a Pterodactyl Panel instance (claimed CVE-2025-49132, affected < v1.11.11). Structure: (1) READme.md documents the vulnerability chain and manual curl steps; (2) exploit.sh is the primary, featureful exploit driver; (3) exploit.py is a simpler Python driver focused on sending a reverse shell. Core technique: abuse /locales/locale.json with a path traversal in the locale parameter to reach the PEAR directory and invoke pearcmd.php via the namespace=pearcmd mechanism. The exploit uses PEAR's config-create command (passed via the crafted query string '+config-create+/') to write an arbitrary PHP file into /tmp (x.php) containing `<?=system(hex2bin('<hex-encoded command>'))?>`. A second request loads locale=../../../../../tmp&namespace=x to execute the dropped PHP and return command output. Capabilities: arbitrary command execution, output scraping/filtering (bash uses an embedded python3 filter; python script filters common HTML/PEAR noise), reverse shell (bash TCP) with a mkfifo+nc fallback in exploit.sh, and basic enumeration/flag-finding helpers in exploit.sh. Hardcoded target is http://panel.pterodactyl.htb and hardcoded PEAR traversal path is ../../../../../../usr/share/php/PEAR.
Repository contains a single Python PoC exploit (CVE-2025-49132-dbs.py) and a README describing an unauthenticated RCE in Pterodactyl Panel <= 1.11.10 (patched in 1.11.11). The exploit is a two-stage, network-based attack against the HTTP endpoint /locales/locale.json: (1) it sends a crafted request using directory traversal in the locale parameter and a pearcmd namespace with a config-create action to write a PHP payload into /tmp/payload.php; the payload is a short PHP snippet that calls system() with the attacker-supplied command (spaces are replaced with an IFS-based sequence). (2) it sends a second request that traverses to /tmp and sets namespace=payload to load/execute the written PHP, resulting in arbitrary command execution. The script uses os.system to invoke curl and accepts --target, --cmd, and optional --path (default /usr/share/php/PEAR). No additional modules, persistence, or post-exploitation automation are included beyond executing a single command.
Repository contains a single shell script exploit: `CVE-2025-49132.sh` (~1.3 KB). It targets CVE-2025-49132 in Pterodactyl Panel, chaining an unauthenticated LFI in `/locales/locale.json` with a PEAR/pearcmd technique to achieve RCE. High-level flow: 1) Takes `[TARGET]` and `[CMD]` as arguments; optionally URL-encodes the command using the external `encode` utility. 2) Generates random identifiers (via `uuidgen`) for a webshell filename and a GET parameter name. 3) Iterates through a hardcoded list of common PEAR include paths (e.g., `/usr/share/php`, `/usr/share/pear`) and for each sends a crafted request to `/locales/locale.json` using `namespace=pearcmd` and a `+config-create+` style argument injection to write a PHP webshell (`eval($_GET[...])`) into `/tmp/<uuid>.php`. 4) Sends a final request that LFI-loads `../../../../../tmp` with `namespace=<uuid>` and passes `<param>=system('<CMD>');die();` to execute the attacker command. Output is extracted with `awk`. Capabilities: unauthenticated remote command execution on the target host (via dropped PHP webshell in /tmp), with basic output retrieval. No persistence beyond the /tmp webshell is implemented, and there is no interactive shell—commands are executed per invocation.
Repository contains a single operational Bash exploit script (exploit.sh) labeled for CVE-2025-49132 and tailored to an HTB target (panel.pterodactyl.htb). The script implements a two-stage network RCE chain using curl: 1) Stage 1 (file write): crafts a request to /locales/locale.json that abuses PEAR/pearcmd 'config-create' behavior to write a PHP file to /tmp/x.php. The PHP payload is a short tag that runs system(hex2bin('<hex-encoded command>')), allowing arbitrary command execution while avoiding problematic characters by hex-encoding. 2) Stage 2 (execution): requests /locales/locale.json with locale=../../../../../tmp and namespace=x to load/execute the previously written /tmp/x.php and return command output. Capabilities include: arbitrary command execution (cmd mode), reverse shell deployment (shell mode) using bash /dev/tcp with a mkfifo+nc fallback, and a convenience 'flag' mode that runs common enumeration and flag-discovery commands (whoami/id, listing /home, find/cat user.txt/root flags). Output is post-processed via an inline Python3 filter to remove HTML/PEAR noise and print likely command results.
Repository contains a Python proof-of-concept exploit for CVE-2025-49132 affecting Pterodactyl Panel <= 1.11.10. Structure: (1) README.md explains the root cause: an unauthenticated route `/locales/locale.json` calls Laravel translation loader with user-controlled `locale` and `namespace` (mapped to group path via `str_replace('.', '/', $namespace)`), enabling path traversal to load arbitrary PHP files (via `getRequire`) and disclose configuration. It also describes leveraging `pearcmd.php` as a write primitive to escalate to RCE. (2) poc.py implements two modes: `check` sends a GET to `/locales/locale.json?locale=../../../pterodactyl&namespace=config/database` and prints the returned JSON (database configuration disclosure). `exploit` constructs a crafted URL intended to traverse into a user-specified PEAR directory and invoke `pearcmd` with `config-create` arguments to write a PHP webshell `cmd.php` containing `<?=system($_GET['cmd']);?>` into a user-specified writable directory (default `/tmp`). Due to URL encoding issues with `requests`, exploit mode executes `curl -g` via subprocess to preserve special characters in the query string. Successful exploitation yields a dropped webshell accessible over HTTP for arbitrary command execution.
Repository contains a single Python exploit script (ape1.py) plus a README describing CVE-2025-49132 against Pterodactyl Panel (<1.11.11). The exploit is unauthenticated and network-based, targeting the panel's /locales/locale.json endpoint. It leverages directory traversal/LFI-style control of the 'locale' parameter to reach a PEAR installation and invoke pearcmd functionality. The script performs a two-step chain: (1) uses a crafted request that calls PEAR's 'config-create' to write a PHP webshell to /tmp/shell.php containing system('<command>') with a space-bypass (${IFS}) transformation; (2) triggers execution by requesting /locales/locale.json with locale pointing to ../../../../../tmp and namespace=shell, causing the dropped shell to be loaded and the command executed. It supports single-command mode, an interactive loop, and a PEAR path discovery routine that probes common filesystem locations by requesting /locales/locale.json?locale=<candidate> and checking responses for PEAR-related keywords. Output parsing attempts to extract command results (e.g., uid=, HTB{ flags) from noisy responses. No hardcoded C2 is present; any callback (e.g., curl|bash reverse shell) is operator-supplied as a command.
Repository contains a single Python exploit (exploit.py) plus a README. It targets CVE-2025-49132 in Pterodactyl Panel <= 1.11.10, abusing an unauthenticated locale loader at /locales/locale.json where locale/namespace are passed to PHP include() without proper sanitization and the intended 'hash' protection is not enforced. Core capability is unauthenticated LFI: the script repeatedly queries /locales/locale.json with crafted locale traversal (default ../../../pterodactyl) and various Laravel config namespaces (e.g., config/database, config/app) to extract secrets such as database credentials, Redis settings, and APP_KEY. In default mode it performs broad config dumping (database/app/pterodactyl/session/auth/services/mail/queue/hashing/cors) and attempts to read extra sensitive files (e.g., /etc/passwd), then writes a consolidated JSON report (loot.json). For RCE, the exploit automates multiple strategies: (1) pearcmd.php inclusion-based RCE, using a raw curl -g subprocess approach to avoid Python requests URL-encoding issues and encoding the command as hex executed via system(hex2bin(...)); supports custom PEAR directories via --pear-dir. (2) PHP filter-chain based execution using php://filter chains (either auto-generated via external generator or supplied via --filter-chain), with a fallback to constructing a raw URL to avoid double-encoding. (3) Laravel deserialization RCE leveraging leaked APP_KEY (imports like hmac/hashlib/base64 and optional pycryptodome/phpggc are referenced in README), indicating it can craft/trigger a signed/encrypted payload once the key is obtained. Overall structure: a PterodactylExploit class encapsulates HTTP session handling, LFI helpers, vulnerability check, config dump routines, and RCE test methods; main() parses CLI options to run a specific RCE mode (--rce-cmd, --rce-filter, --rce-d) or default full-dump + automated RCE attempts.
Repository contains a single Python PoC exploit (CVE-2025-49132_POC.py) and a README. The script is an operational RCE chain delivered over HTTP using curl via os.system(). It targets a vulnerable web application endpoint at /locales/locale.json, leveraging query parameters that include '+config-create+' plus directory traversal in the 'locale' parameter to reach the PEAR installation path and invoke 'pearcmd' (namespace=pearcmd). The exploit runs two command-execution stages: (1) create an intermediate file (1.txt) containing base64-encoded PHP code for a webshell, and (2) decode that base64 into webshell.php. After the webshell is in place, it calls /webshell.php?cmd=... to execute a URL-encoded bash reverse shell that connects back to the attacker-controlled IP and port. The PoC requires the operator to edit hardcoded variables (host, pear_path, your_ip, your_port) and to run a listener (e.g., nc) to receive the shell. No framework integration is present; it is a standalone exploit script focused on reverse-shell outcome rather than vulnerability detection.
Repository contains a single Python PoC script plus README and MIT license. The script (`CVE-2025-49132-PoC.py`) targets CVE-2025-49132 in Pterodactyl Panel (<1.11.11), abusing an unauthenticated path traversal in the locale loading endpoint (`/locales/locale.json`) to (1) test for vulnerability, (2) read configuration data and dump database credentials, and (3) attempt a limited RCE chain. Structure/purpose: - `CVE-2025-49132-PoC.py`: Main entry point. Implements three modes via argparse: `test`, `dump`, `exploit`. It builds traversal strings (`../` or URL-encoded backslash for Windows) with a configurable `--traversal-level` and crafts GET requests to the locale endpoint with different `namespace` values. - `README.md`: Describes the vulnerability, affected versions, usage examples, and basic opsec notes. - `LICENSE`: MIT. Key capabilities: - Unauthenticated vulnerability check: requests `namespace=config/app` and looks for a Pterodactyl string in the response. - Credential/config disclosure: requests `namespace=config/database`, parses JSON, and prints MySQL host/port/database/username/password. - Limited RCE demonstration: crafts a `pearcmd`-style request intended to write a PHP payload (`<?php sleep(5); ?>`) to `/tmp/payload.php`, then triggers it via another locale load and infers success by measuring a ~5 second delay. Notable implementation details: - Uses `requests` with TLS verification disabled (`verify=False`) and suppresses urllib3 warnings. - OS toggle changes traversal separator (`/` vs `%5c`) and PEAR base path assumptions (`/usr/local/lib/php` vs `C:/php`). - RCE success is heuristic (timing-based), not output-based.
This repository contains a Python exploit script (CVE-2025-49132.py) and a README.md. The exploit targets CVE-2025-49132, a critical vulnerability in the Pterodactyl game server management panel. The script performs a mass scan of provided URLs, attempting to exploit a path traversal vulnerability in the /locales/locale.json endpoint. By manipulating the 'locale' and 'namespace' parameters, the script attempts to retrieve sensitive configuration data, specifically MySQL database credentials, from the target. If successful, the credentials are saved to credentials.txt. The script supports multithreaded scanning and is designed for operational use against multiple targets. The README provides a brief description of the vulnerability, search dorks for finding targets, and example payloads. The exploit is not a detection script; it actively extracts sensitive data, making it operational in maturity.
This repository contains a Python exploit tool targeting CVE-2025-49132, a misconfiguration vulnerability in Pterodactyl Panel. The exploit automates the process of discovering vulnerable panels by attempting to access the '/locales/locale.json' endpoint with specific query parameters. If the endpoint is exposed, the tool extracts MySQL database credentials from the returned configuration. It then attempts to connect to the MySQL database and inserts a new admin user, granting the attacker full access to the panel. The tool can process multiple targets from a file ('list.txt'), skips panels protected by Cloudflare, and provides detailed output for each step. The repository consists of a single main exploit script ('cve.py') and a README with usage instructions. The exploit is operational and provides a working payload for privilege escalation on vulnerable Pterodactyl panels.
This repository provides a Python proof-of-concept exploit for CVE-2025-49132. The exploit consists of a single script (poc.py) and a README.md with usage instructions and background information. The script allows an attacker to execute arbitrary system commands on a vulnerable target by leveraging a path traversal and PHP code injection vulnerability. The exploit works by sending two HTTP GET requests to the /locales/locale.json endpoint on the target: the first request creates a PHP payload file on the target system, and the second request triggers execution of the payload, returning the output of the command. The script uses the 'requests' library for HTTP communication and provides a command-line interface for specifying the target host and command to execute. The exploit is a proof-of-concept and does not include advanced features such as payload customization or post-exploitation modules. The main attack vector is network-based, targeting a web application endpoint. The repository is well-structured, with clear separation between documentation and exploit code.
This repository provides a proof-of-concept exploit for CVE-2025-49132, a file inclusion vulnerability in the Pterodactyl Panel. The exploit consists of a single Python script (poc.py) and a README.md with usage instructions. The script takes a target host and a shell command as arguments, then crafts two HTTP requests to the target: the first writes a PHP payload to /tmp/payload.php via a file inclusion vulnerability in the pearcmd.php script, and the second triggers execution of the payload. The exploit demonstrates remote code execution by creating a file on the target. The repository is structured simply, with clear separation between documentation and exploit code, and is intended for demonstration and testing of the vulnerability.
This repository provides exploit code for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions 1.9.0 through 1.11.10. The repository contains three main Python scripts: - 'exploit.py': The primary exploit script, which first checks if the target is vulnerable by sending a crafted HTTP request to the '/locales/locale.json' endpoint with path traversal in the 'locale' parameter. If vulnerable, it attempts to write a PHP payload to the server's filesystem (e.g., '/tmp/payload.php') for remote code execution. - 'dump-creds.py': A script to extract sensitive configuration data from the target, including the application key, database, filesystem, and mail configuration, by abusing the same path traversal vulnerability. - 'test.py': A simple script to check if the target is vulnerable, without further exploitation. The exploit leverages a path traversal flaw in the 'locale' parameter of the Pterodactyl Panel's '/locales/locale.json' endpoint, allowing attackers to read arbitrary configuration files and, in some cases, write a PHP payload for code execution. The attack is performed over HTTP(S) and targets Linux systems running the affected Pterodactyl Panel versions. No hardcoded IPs or domains are present; the scripts require the user to supply the target URL. The repository is operational, providing both proof-of-concept and working exploit code.
This repository contains a Python exploit targeting the Pterodactyl Panel's path traversal vulnerability (GHSA-24wv-6c99-f843). The exploit consists of two main scripts: 1. `forge_cookie.py`: This script forges a valid Laravel session cookie (`pterodactyl_session`) using a stolen APP_KEY and a session ID. It mimics Laravel's encryption and signing process, allowing the attacker to generate a cookie that will be accepted by the Pterodactyl Panel for API authentication. The script requires the attacker to have already obtained the APP_KEY and Redis credentials, typically via an exposed Redis server and access to the server's configuration file. 2. `illuminate-decryptor.py`: This script is a utility to decrypt Laravel session cookies, useful for analyzing or verifying the contents of a session cookie if the APP_KEY is known. The README provides a step-by-step guide for using the exploit, emphasizing that only API access is possible (not full web panel login) due to additional authentication requirements. The exploit is operational, requiring some manual steps to obtain necessary secrets, and is not weaponized for automated mass exploitation. The main attack vector is network-based, targeting exposed Redis servers and the Pterodactyl Panel's API endpoint. No hardcoded IPs or domains are present; all endpoints are user-supplied.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.