GHSA-6rg3-8h8x-5xfv

    Dashboard / Vulnerabilities / GHSA-6rg3-8h8x-5xfv

    GHSA-6rg3-8h8x-5xfv

    Published: 23 Jun 2021Last Modified: 4 Feb 2026

    Summary: Unchecked hostname resolution could allow access to local network resources by users outside the local network

    Details: ### Impact A newly implemented route allowing users to download files from remote endpoints was not properly verifying the destination hostname for user provided URLs. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible. This vulnerability requires valid authentication credentials and is therefore **not exploitable by unauthenticated users**. If you are running an instance for yourself or other trusted individuals this impact is unlikely to be of major concern to you. However, you should still upgrade for security sake. ### Patches Users should upgrade to the latest version of Wings. ### Workarounds There is no workaround available that does not involve modifying Panel or Wings code.

    Affected packages

    Package

    Name: github.com/pterodactyl/wings

    Purl: pkg:golang/github.com/pterodactyl/wings

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.2.0
    Fixed -1.2.1

    Affected versions

    1.2.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6rg3-8h8x-5xfv | CVE-DB