ZeroHour

CVE-2026-13716

PoC ×2niche

Authenticated Path Traversal to RCE in Crafty Controller

CVSS 3.1
9.1 critical
EPSS
<1%p52
Published
()
Modified
AI analysis

Crafty Controller, an open-source web panel for managing game servers, contains a path-traversal flaw (CWE-35) in its server import and administrator file-upload features. An attacker holding valid, low-privilege authentication credentials can upload crafted files to arbitrary filesystem paths that the application is permitted to write. By placing attacker-controlled files in privileged locations, the attacker achieves remote code execution on the host running the panel, consistent with the changed-scope (S:C) component of the 9.1 CVSS score. The flaw affects Crafty Controller deployments; the published references point to the Crafty 4 (crafty-4) codebase, but no specific vulnerable version ranges were provided in the available data. There is currently no evidence of exploitation in the wild (not listed in CISA KEV, EPSS 0.7%), and two public PoC/tracker references exist, so defenders should treat this as a critical but not yet actively exploited issue.

What to do: Upgrade Crafty Controller to the latest release as soon as the vendor's fix is published, and monitor the vendor's GitLab work items (727 and 740) for the patched version and affected version ranges. Until patched, restrict who has valid panel credentials, limit the panel's internet exposure (VPN or allowlist), and consider disabling or tightly controlling the server import and admin file-upload features. Review application and web logs for unexpected file uploads or writes to unusual paths.

Affected
craftycontrol Crafty Controller
Estimated exposure
nichelikely low thousands to low tens of thousands of self-hosted panels (order-of-magnitude estimate) — No official install counts were provided; Crafty Controller is a self-hosted Minecraft server management panel typically deployed as a single instance per administrator or small hosting operation, so exposure is bounded by the project's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

Vendors
craftycontrol
Products
crafty controller
Weakness
CWE-35
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.