CVE-2026-48991: XianYuLauncher Authentication Token Exposure (v<1.5.5)
XianYuLauncher, a popular Minecraft Java Edition launcher, has a flaw in versions before 1.5.5 that allows a local attacker to steal authentication credentials during the login process. The vulnerability exists because the launcher uses a simple, predictable method to handle login on your computer without adequate security checks. If someone else can access your device or monitor your network traffic locally, they could intercept the authentication tokens needed to access your Minecraft account. The risk is highest in shared or untrusted computing environments. Updating to version 1.5.5 or later closes this gap.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-287
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-22
NVD description (verbatim)
XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Exploitation is most likely to occur when an attacker is able to observe, intercept, or otherwise interfere with the local authentication flow on the same device. This issue has been fixed in version 1.5.5.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
XianYuLauncher prior to v1.5.5 employs insufficient OAuth 2.0 security controls during local authentication. Specifically, the launcher redirects authentication responses to a fixed localhost URI without implementing PKCE (Proof Key for Public Clients) or state parameter validation. This design flaw maps to CWE-287 (Improper Authentication) and creates an avenue for token leakage under local threat scenarios. An attacker positioned to observe or manipulate the local HTTP redirect flow—such as a process interceding on the same machine or an adversary with network access on an isolated segment—can capture the authorization code or access token before it is securely stored. The absence of state validation further prevents the client from confirming that the response corresponds to its own request, enabling potential authorization code injection attacks.
Business impact
For organizations or individuals relying on XianYuLauncher for Minecraft Java Edition, account compromise could lead to loss of in-game progress, access to linked Microsoft or Mojang accounts, and potential lateral movement if the same credentials are reused elsewhere. In corporate or educational environments where Minecraft is used for training or collaboration, unauthorized account takeover could disrupt operations or enable further social engineering. The localized nature of the threat means impact is limited to single-device compromise scenarios, but the ease of exploitation in multi-user or shared-device contexts should not be underestimated.
Affected systems
All XianYuLauncher installations running versions prior to 1.5.5 are vulnerable. The flaw affects both Windows and other platforms on which the launcher operates. Users who have not yet upgraded are at risk, particularly in environments where local access controls are weak or where multiple users share a single device.
Exploitability
Exploitability is rated as straightforward for an attacker with local access or the ability to monitor local network traffic. The vulnerability requires user interaction (the user must initiate a login) and local system or network positioning, which limits the attack surface to specific threat actors and scenarios. No network-level authentication is required; the attacker does not need valid credentials or administrative privileges to attempt interception. Once in position, the absence of PKCE and state validation makes token capture and misuse trivial.
Remediation
Upgrade XianYuLauncher to version 1.5.5 or later. This release implements PKCE and state parameter validation, both industry-standard OAuth 2.0 security controls that prevent token interception and code injection attacks. Verify the upgrade through the launcher's built-in update mechanism or download the latest version from the official source. For organizations that cannot immediately patch, restrict launcher use to trusted, single-user devices and monitor for unusual account access patterns.
Patch guidance
Version 1.5.5 is the minimum secure version. Users should enable automatic updates if available or manually download and install the latest release from the official XianYuLauncher repository. Patch deployment is recommended as soon as feasible, with priority given to systems in multi-user or guest-accessible environments. No interim workarounds are known; patching is the only reliable remediation.
Detection guidance
Monitor for suspicious login activity on Minecraft accounts, including failed authentication attempts or logins from unusual locations or times. On the system level, check for process-level interception of HTTP requests to localhost redirect URIs (typically port 8000–9000 range) during launcher authentication flows. Log review for unauthorized access or modifications to launcher configuration files may reveal prior compromise. Correlate account access logs with launcher version information to identify affected installations.
Why prioritize this
Although the CVSS score of 5.5 (Medium) reflects limited scope and local-only attack constraints, the ease of exploitation and direct threat to user account integrity justify prompt attention. The vulnerability affects gaming infrastructure that may be used in corporate training or education, and account compromise can facilitate credential stuffing attacks if users reuse passwords across services. Organizations should prioritize patching in environments where shared or guest device access is common.
Risk score, explained
The CVSS 3.1 score of 5.5 (Medium) reflects a local attack vector with no privilege requirement and relatively low attack complexity. High confidentiality impact (C:H) is offset by the fact that no integrity or availability impact occurs, and the attack is limited to the local scope (S:U). User interaction is required to trigger the vulnerability. While the score is not critical, the practical ease of exploitation in multi-user scenarios and the direct threat to user credentials warrant consideration of context-specific risk elevation.
Frequently asked questions
Do I need to worry about this if I am the only user on my device?
Your risk is lower but not zero. If your device is ever accessed by guests, used in a repair shop, or if you use public Wi-Fi near others running similar software, a local attacker could still intercept your login. Updating to 1.5.5 is still recommended as a defensive measure.
Will updating to 1.5.5 affect my existing Minecraft worlds or account settings?
No. Version 1.5.5 only changes the authentication mechanism; it does not modify game data, worlds, or account configuration. Your launcher settings and linked accounts will remain intact.
Is there any public exploit code for this vulnerability?
As of publication, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no widespread public weaponization has been reported. However, the simplicity of the underlying flaw means an attacker with local access could develop an exploit with minimal effort.
What should I do if I think my Minecraft account has been compromised?
Change your Minecraft/Microsoft account password immediately, enable two-factor authentication if available, and check your account activity for unauthorized logins or purchases. If you use the same credentials elsewhere, change those passwords as well. Contact Minecraft support if you suspect unauthorized access.
This analysis is provided for informational purposes and based on available vulnerability data as of the publication date. Security teams should verify patch availability and compatibility with their specific environment before deployment. No warranty is provided regarding the completeness or accuracy of this analysis. Consult official vendor advisories and your organization's security policies for authoritative guidance. This document does not constitute legal or compliance advice. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2023-5502MEDIUMArista EOS 802.1x Authentication Bypass Vulnerability
- CVE-2026-10283MEDIUMBottelet DaybydayCRM Authentication Bypass in Settings Handler
- CVE-2026-10548MEDIUMImproper Authentication in NousResearch hermes-agent Credential Synchronization
- CVE-2026-35261MEDIUMOracle Access Manager Authentication Bypass (CVSS 6.5)
- CVE-2026-40995MEDIUMSpring Web Services X509 Authentication Bypass Accounting Lifecycle Checks
- CVE-2026-45153MEDIUMNextcloud Android Files App PIN Bypass via Back Button
- CVE-2026-45283MEDIUMNextcloud File Lock Authorization Bypass
- CVE-2026-45289MEDIUMCloudburstMC Protocol Authentication Validation Bypass (MEDIUM)