Executive brief
MythicalDash is a hosting panel for Pterodactyl servers that uses Stripe for billing. A flaw in the payment verification endpoint allows an authenticated user to claim an arbitrary amount of free virtual currency (coins) without actually paying for it. An attacker can start a purchase, read the payment code, abandon the transaction, and directly request credit for any amount they choose, enabling free resource consumption and direct financial loss to operators.
Technical details
The vulnerability is a combination of missing authentication (CWE-862) and missing payment verification (CWE-345) in the GET /api/stripe/processed endpoint. While the sibling /api/stripe/process endpoint is properly authenticated via Session, the processed endpoint performs no session check and accepts payment requests based solely on a query-string code. Additionally, the endpoint trusts that a pending code implies successful Stripe payment without ever calling Stripe::Checkout::Session::retrieve or validating payment_status === 'paid' and amount_total. An authenticated user can initiate a top-up with an attacker-chosen coin amount, extract the code from the Stripe success_url, abandon or fail the payment, and call /api/stripe/processed?code=<code> directly to receive full credit for free. The fix requires authentication check on the processed endpoint, owner verification of the payment code, and explicit Stripe payment status confirmation.
Affected products
- Mythical Systems MythicalDash 3.5.4-aurora and earlier
Timeline
- 2026-09-17: disclosed: CVE-2026-54608 published
- patched: Fix available via commit 188d4c4; no formal release with patch confirmed as of advisory date