๐Ÿ” CVE Alert

CVE-2026-54608

UNKNOWN 0.0

MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed accepts that code without constructing a Session, checking ownership, or retrieving the Stripe Checkout Session to require payment_status to be paid and amount_total to match the expected charge. An ordinary authenticated user can request an attacker-selected coins amount, abandon or fail payment, and submit the pending code directly to the unauthenticated processed endpoint. StripeDB::isPending() then permits User::addCreditsAtomic() to grant the unpaid amount and mark the row processed even though Stripe has not confirmed payment. This permits arbitrary free virtual-currency top-ups and direct financial loss through consumption of hosting resources. No fixed version is available as of this review.

CWE CWE-345 CWE-862
Vendor mythicalltd
Product mythicaldash
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for mythicalltd mythicaldash

Be the first to know when new unknown vulnerabilities affecting mythicalltd mythicaldash are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MythicalLTD / MythicalDash
<= 3.5.4-aurora

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MythicalLTD/MythicalDash/security/advisories/GHSA-qmh4-5v7g-42jq github.com: https://github.com/MythicalLTD/MythicalDash/commit/188d4c4ed80b8d364b0c4605a9e38ceaab746e39