Vulnerability Description
MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed accepts that code without constructing a Session, checking ownership, or retrieving the Stripe Checkout Session to require payment_status to be paid and amount_total to match the expected charge. An ordinary authenticated user can request an attacker-selected coins amount, abandon or fail payment, and submit the pending code directly to the unauthenticated processed endpoint. StripeDB::isPending() then permits User::addCreditsAtomic() to grant the unpaid amount and mark the row processed even though Stripe has not confirmed payment. This permits arbitrary free virtual-currency top-ups and direct financial loss through consumption of hosting resources. No fixed version is available as of this review.
Related Weaknesses (CWE)
References
- https://github.com/MythicalLTD/MythicalDash/commit/188d4c4ed80b8d364b0c4605a9e38
- https://github.com/MythicalLTD/MythicalDash/security/advisories/GHSA-qmh4-5v7g-4
- https://github.com/MythicalLTD/MythicalDash/security/advisories/GHSA-qmh4-5v7g-4
FAQ
What is CVE-2026-54608?
CVE-2026-54608 is a documented vulnerability. MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments befo...
How severe is CVE-2026-54608?
CVSS scoring is not yet available for CVE-2026-54608. Check NVD for updates.
Is there a patch for CVE-2026-54608?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.