PT-2026-95143 · Unknown · Mythicaldash

·

CVE-2026-54608

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MythicalDash versions prior to 3.5.4-aurora
Description An unauthenticated payment bypass exists in the Stripe success-redirect mechanism. The endpoint '/api/stripe/process' creates a pending payment record before checkout is completed and includes a payment code in the success redirect. Subsequently, the endpoint '/api/stripe/processed' accepts this code without verifying the session, checking ownership, or confirming that the payment status is paid and the total amount matches the expected charge. An authenticated user can request a specific amount of coins, fail or abandon the payment, and then submit the pending code to the '/api/stripe/processed' endpoint. This allows the StripeDB::isPending() function to trigger User::addCreditsAtomic(), granting unpaid credits and marking the transaction as processed. This flaw enables arbitrary free virtual-currency top-ups, leading to financial loss through the unauthorized consumption of hosting resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54608
GHSA-QMH4-5V7G-42JQ

Affected Products

Mythicaldash