blob: 0a74e58b3a23a6c5b91277344836cab9a80ccd9e [file]
id: GO-2026-4283
modules:
- module: github.com/pterodactyl/wings
versions:
- fixed: 1.12.0
vulnerable_at: 1.11.13
summary: |-
Pterodactyl does not revoke SFTP access when server is deleted or permissions
reduced in github.com/pterodactyl/wings
cves:
- CVE-2025-68954
ghsas:
- GHSA-8c39-xppg-479c
references:
- advisory: https://github.com/pterodactyl/panel/security/advisories/GHSA-8c39-xppg-479c
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-68954
- web: https://github.com/pterodactyl/panel/commit/2bd9d8baddb0e0606e4a9d5be402f48678ac88d5
- web: https://github.com/pterodactyl/panel/releases/tag/v1.12.0
source:
id: GHSA-8c39-xppg-479c
created: 2026-01-12T11:48:05.395119245-05:00
review_status: UNREVIEWED