
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical unauthenticated remote code execution (RCE) vulnerability in Pterodactyl Panel versions prior to 1.11.11.
/locales/locale.json endpoint, exploitable via the locale and namespace query parameters. This allows attackers to execute arbitrary code, read sensitive files (e.g., configs, .env), dump databases, and access managed servers.The script CVE-2025-49132-PoC.py is an automated tool that can:
It supports both Linux and Windows targets by adjusting path separators. Includes colored output and error handling for better usability.
python CVE-2025-49132-PoC.py <mode> <http://host> [--os <linux|windows>] [--traversal-level <int>]
#Example of commands
python CVE-2025-49132-PoC.py test http://sub.domain.com
python CVE-2025-49132-PoC.py dump http://domain.com
python CVE-2025-49132-PoC.py exploit http://sub.domain.com --os linux
python CVE-2025-49132-PoC.py test http://sub.domain.com --os linux --traversal-level 3
If the check fails, review the printed URL, status, and response. The response may be HTML if the endpoint is blocked or not vulnerable. Ensure the host is correct and reachable.
This PoC is provided for educational purposes only or for use in authorized challenges such as CTFs (Capture The Flag) or penetration testing with explicit permission. It is illegal to use this against any system without prior written consent from the owner. The author assumes no liability for any misuse of this code.
Requires Python 3 and requests (install via pip install requests).
MIT License. See LICENSE file.
Pull requests are welcome for improvements, but ensure they align with educational intent.