pterodactyl
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 29, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered
Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances
Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
Pterodactyl TOTPs can be reused during validity window
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Arbitrary File Write/Read in Pterodactyl wings
Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel
Server-side Request Forgery during remote file pull in Pterodactyl wings
Monitor pterodactyl in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.