Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-pfvc-3p5h-x7h6
No affected components available
Impact
Type: Exposure of sensitive information / insufficiently protected credentials leading to privilege escalation and full node compromise.
Wings exposes its entire daemon configuration to the egg configuration-file
templating engine. When Wings renders a server's configuration files, any
{{config.<path>}} placeholder in a replacement value is resolved against the
full marshalled daemon configuration, with no restriction on which paths may be
read.
Because the Panel substitutes user-controlled egg variable values into these
replacements before sending them to Wings, a low-privileged user can smuggle a
{{config.*}} placeholder through a variable value. The placeholder is then
resolved by Wings and written into a file inside the user's own server, where it
can be read via the file manager or SFTP.
This allows reading, among other values:
{{config.token}}- the node's daemon token, which is both the API bearer for the Panel⇆Wings channel and the HMAC signing key for every JWT the node issues;{{config.token_id}};{{config.docker.registries}}- configured container-registry credentials.
Who is impacted: Any deployment where a user who is not fully trusted can set
an egg variable value (e.g. a server owner or a subuser with the startup.update
permission) and the server's egg renders a user-editable variable into a
configuration file via {{server.build.env.*}}. This pattern is common across
stock and community eggs, so most multi-tenant / shared-hosting deployments are
affected.
Resulting impact: Disclosure of the node daemon token lets the attacker forge authentication tokens and act against every server on that node, a full-node compromise reachable from a low-privileged account.
Patches
Yes. Fixed in Wings v1.12.3 (Panel is unaffected; the fix is Wings-only).
Wings no longer exposes its full configuration to the templating engine only an
explicit, non-secret subset (the Docker network interface) can be resolved by
{{config.*}} placeholders.
Users should upgrade Wings to v1.12.3 or later.
After upgrading, rotate the affected nodes' daemon tokens, since a previously
exfiltrated token remains valid until rotated (Admin → Nodes → Configuration →
reset the token, then re-deploy config.yml to the node).
Workarounds
For operators who cannot upgrade immediately:
- Audit your eggs and ensure no user-editable variable is rendered into a configuration file, or mark such variables non-editable.
These reduce exposure but are not a complete fix; upgrading Wings is the recommended action.
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The vulnerability can affect other systems as well, not just the initial system. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.
Active exploitation in the wild has been confirmed. Immediate patching or mitigation is required.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard