PT-2026-56106 · Go · Github.Com/Pterodactyl/Wings

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
In wings/internal/ufs/fs unix.go (line 92-94), this function is defined and is used to change permissions of files in the server:
go
func (fs *UnixFS) fchmodat(op string, dirfd int, name string, mode FileMode) error {
  return ensurePathError(unix.Fchmodat(dirfd, name, uint32(mode), 0), op, name)
}
This call to the unix function fchmodat(int fd, char* name, mode t mode, int flags) does not have the flag AT SYMLINK NOFOLLOW set, and Wings neither checks or validate if the target file is a symlink. This allows one to change permissions of files or folders outside of the server container by making symlinks to existing files in the host and then chmoding it.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-RHQ6-9RGH-V45C

Affected Products

Github.Com/Pterodactyl/Wings