Description
MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed accepts that code without constructing a Session, checking ownership, or retrieving the Stripe Checkout Session to require payment_status to be paid and amount_total to match the expected charge. An ordinary authenticated user can request an attacker-selected coins amount, abandon or fail payment, and submit the pending code directly to the unauthenticated processed endpoint. StripeDB::isPending() then permits User::addCreditsAtomic() to grant the unpaid amount and mark the row processed even though Stripe has not confirmed payment. This permits arbitrary free virtual-currency top-ups and direct financial loss through consumption of hosting resources. No fixed version is available as of this review.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized free virtual currency top‑up enabling financial loss
Action: Patch Immediately
AI Analysis

Impact

An authenticated user can request a pending payment code for an arbitrary coin amount, abandon the Stripe checkout, and then submit that code to the unauthenticated /api/stripe/processed endpoint. The backend allows the code to be accepted without verifying ownership, without confirming that Stripe’s session status is ‘paid’, and without matching the amount charged. As a result the system grants the full credit amount by calling User::addCreditsAtomic(), creating free virtual currency for the attacker. This is an authorization bypass that directly leads to financial loss by draining hosting resources, and it aligns with CWE-345 and CWE-862.

Affected Systems

MythicalLTD’s MythicalDash, versions 3.5.4‑aurora and prior, are affected because the vulnerable GET /api/stripe/process endpoint creates a pending database row and the later /api/stripe/processed route can accept that row without proper ownership or payment validation.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate impact. The EPSS score of less than 1 % suggests that exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog, but the risk remains due to the lack of a current patch. The likely attack vector is a standard HTTP GET request from any host that can reach the MythicalDash server. An attacker who has legitimate credentials can exploit the flow to hijack credits and incur unanticipated costs.

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Await the official patch from MythicalLTD and apply it as soon as it is released
  • Add an authentication check to the /api/stripe/processed endpoint so that only the payment owner or an administrator can use it
  • Enforce server‑side validation of Stripe’s Checkout Session status and amount before awarding credits

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mythicalltd
Mythicalltd mythicaldash
Vendors & Products Mythicalltd
Mythicalltd mythicaldash

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed accepts that code without constructing a Session, checking ownership, or retrieving the Stripe Checkout Session to require payment_status to be paid and amount_total to match the expected charge. An ordinary authenticated user can request an attacker-selected coins amount, abandon or fail payment, and submit the pending code directly to the unauthenticated processed endpoint. StripeDB::isPending() then permits User::addCreditsAtomic() to grant the unpaid amount and mark the row processed even though Stripe has not confirmed payment. This permits arbitrary free virtual-currency top-ups and direct financial loss through consumption of hosting resources. No fixed version is available as of this review.
Title MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up
Weaknesses CWE-345
CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mythicalltd Mythicaldash
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:12:23.118Z

Reserved: 2026-06-15T19:45:23.540Z

Link: CVE-2026-54608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:01.233

Modified: 2026-09-23T19:43:31.933

Link: CVE-2026-54608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-862

    Missing Authorization