CVE-2026-13716
PoC ×2nicheAuthenticated Path Traversal to RCE in Crafty Controller
Crafty Controller, an open-source web panel for managing game servers, contains a path-traversal flaw (CWE-35) in its server import and administrator file-upload features. An attacker holding valid, low-privilege authentication credentials can upload crafted files to arbitrary filesystem paths that the application is permitted to write. By placing attacker-controlled files in privileged locations, the attacker achieves remote code execution on the host running the panel, consistent with the changed-scope (S:C) component of the 9.1 CVSS score. The flaw affects Crafty Controller deployments; the published references point to the Crafty 4 (crafty-4) codebase, but no specific vulnerable version ranges were provided in the available data. There is currently no evidence of exploitation in the wild (not listed in CISA KEV, EPSS 0.7%), and two public PoC/tracker references exist, so defenders should treat this as a critical but not yet actively exploited issue.
What to do: Upgrade Crafty Controller to the latest release as soon as the vendor's fix is published, and monitor the vendor's GitLab work items (727 and 740) for the patched version and affected version ranges. Until patched, restrict who has valid panel credentials, limit the panel's internet exposure (VPN or allowlist), and consider disabling or tightly controlling the server import and admin file-upload features. Review application and web logs for unexpected file uploads or writes to unusual paths.
| craftycontrol Crafty Controller | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
- Vendors
- craftycontrol
- Products
- crafty controller
- Weakness
- CWE-35
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.