medium

GHSA-rhq6-9rgh-v45c

Go · github.com/pterodactyl/wings

Summary

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

Severity
medium
CVSS
5
Published
2026-06-26
Updated
2026-06-26

Advisory details

In wings/internal/ufs/fs_unix.go (line 92-94), this function is defined and is used to change permissions of files in the server:

func (fs *UnixFS) fchmodat(op string, dirfd int, name string, mode FileMode) error {
   return ensurePathError(unix.Fchmodat(dirfd, name, uint32(mode), 0), op, name)
}

This call to the unix function fchmodat(int fd, char* name, mode_t mode, int flags) does not have the flag AT_SYMLINK_NOFOLLOW set, and Wings neither checks or validate if the target file is a symlink. This allows one to change permissions of files or folders outside of the server container by making symlinks to existing files in the host and then chmoding it.

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.