---
id: GHSA-rhq6-9rgh-v45c
title: >-
  Pterodactyl Wings: Chmod operation can be used to change permissions of files
  outside of the server container
summary: >-
  Pterodactyl Wings: Chmod operation can be used to change permissions of files
  outside of the server container
severity: medium
cvss: 5
vendor: pterodactyl
product: github.com/pterodactyl/wings
ecosystem: go
affected:
  - 'github.com/pterodactyl/wings >= 1.11.9, < 1.12.2'
patched:
  - github.com/pterodactyl/wings 1.12.2
published: '2026-06-26'
updated: '2026-06-26'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-rhq6-9rgh-v45c'
references:
  - url: >-
      https://github.com/pterodactyl/wings/security/advisories/GHSA-rhq6-9rgh-v45c
  - url: 'https://github.com/advisories/GHSA-rhq6-9rgh-v45c'
tags:
  - ghsa
  - go
ingestedAt: '2026-06-29T13:24:35.261Z'
---

## Overview

In `wings/internal/ufs/fs_unix.go` (line 92-94), this function is defined and is used to change permissions of files in the server:

```go
func (fs *UnixFS) fchmodat(op string, dirfd int, name string, mode FileMode) error {
   return ensurePathError(unix.Fchmodat(dirfd, name, uint32(mode), 0), op, name)
}
```

This call to the unix function `fchmodat(int fd, char* name, mode_t mode, int flags)`  does not have the flag `AT_SYMLINK_NOFOLLOW` set, and Wings neither checks or validate if the target file is a symlink. This allows one to change permissions of files or folders outside of the server container by making symlinks to existing files in the host and then chmoding it.

## Affected packages

- `github.com/pterodactyl/wings >= 1.11.9, < 1.12.2`

## Remediation

Upgrade to a patched release:

- `github.com/pterodactyl/wings 1.12.2`
