Catalyst Remote Code Execution Vulnerability on Game Server Nodes

Vulnerability

A remote code execution vulnerability has been identified in the Catalyst platform, which is used for managing game server hosts and communities. The issue arises because installation scripts in server templates are executed directly on the host operating system as root, without any sandboxing or containerization. This vulnerability affects all versions of the Catalyst agent.

Impact

Exploitation of this vulnerability allows for full root-level remote code execution on any node machine within the Catalyst cluster.

Reproduction

To reproduce this vulnerability, a user must have 'template.create' permission and either 'admin.write' or 'node access' to create servers. Once these conditions are met, a malicious template can be created with an install script that, when executed, performs unauthorized actions such as exfiltrating sensitive files or downloading and executing additional payloads. After the template is applied to a server, the install script runs as root on the host, providing a foothold for further exploitation.

Remediation

Users are advised to update to the patched version of Catalyst, available in commit 11980aaf3f46315b02777f325ba02c56b110165d.

Added: Feb 10, 2026, 9:13 PM
Updated: Feb 11, 2026, 3:01 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.1
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.