Description
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in components/launchserver/src/main/java/pro/gravit/launchserver/socket/handlers/fileserver/FileServerHandler.java strips the first request-target character and resolves the remaining path against updatesDir without re-normalizing and verifying containment. This leaves parent-directory components in a no-leading-slash request and allows reading any file accessible to the LaunchServer process, including .keys/ecdsa_id, .keys/legacySalt, and LaunchServer.json. Disclosure of those files can expose signing keys, refresh-token material, and database credentials, enabling forged administrative access tokens and full authentication bypass. A normalizing L7 proxy may block the primary request form, but direct exposure and L4/TCP proxies remain affected, and netty.fileServerEnabled is enabled by default. This issue is fixed in 5.7.12.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Directory Traversal and Credential Disclosure
Action: Immediate Patch
AI Analysis

Impact

The LaunchServer in GravitLauncher hosts a file server listening on port 9274 that accepts raw HTTP requests lacking a leading slash. During request processing the server strips the first character of the request‑target and resolves the remainder against the updates directory without normalizing or checking that the resolved path remains inside the intended directory. This oversight allows an unauthenticated attacker to traverse parent directories and read any file that the LaunchServer process can access, such as signing key files, token salts, and database credentials. Access to these artifacts gives an attacker the ability to forge administrative access tokens and bypass the authentication system. The flaw is a path traversal vulnerability (CWE‑22) that also results in information disclosure (CWE‑200) and credential storage weakness (CWE‑522).

Affected Systems

The vulnerability affects all releases of GravitLauncher Launcher prior to version 5.7.12. The affected component is the FileServerHandler within the LaunchServer module. No other products or versions have been identified as vulnerable in the available data.

Risk and Exploitability

The CVSS score of 9.8 classifies this as Critical. The EPSS score of <1 % indicates a low probability of exploitation in the wild, yet the unauthenticated and remote nature of the flaw means that an attacker can exploit it from any reachable host. The weakness is not currently listed in the CISA KEV catalog. Direct exposure to the server, or exposure via port‑forwarding or L4 proxies, remains possible. Even a normalizing L7 proxy may block the primary request form, but an attacker can still send a request without a leading slash over a raw TCP connection, making mitigation largely dependent on disabling the file server or patching the software.

Generated by OpenCVE AI on September 19, 2026 at 03:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the GravitLauncher 5.7.12 release or newer, which patches the FileServerHandler path handling logic.
  • If an immediate upgrade is not feasible, set netty.fileServerEnabled to false in the LaunchServer configuration to disable the vulnerable file server.
  • Block or limit external access to TCP port 9274 with a firewall or reverse proxy so that only trusted hosts can reach the LaunchServer.

Generated by OpenCVE AI on September 19, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5g75-477j-2c2f LaunchServer FileServerHandler has an unauthenticated path traversal issue
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gravitlauncher
Gravitlauncher launcher
Vendors & Products Gravitlauncher
Gravitlauncher launcher
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in components/launchserver/src/main/java/pro/gravit/launchserver/socket/handlers/fileserver/FileServerHandler.java strips the first request-target character and resolves the remaining path against updatesDir without re-normalizing and verifying containment. This leaves parent-directory components in a no-leading-slash request and allows reading any file accessible to the LaunchServer process, including .keys/ecdsa_id, .keys/legacySalt, and LaunchServer.json. Disclosure of those files can expose signing keys, refresh-token material, and database credentials, enabling forged administrative access tokens and full authentication bypass. A normalizing L7 proxy may block the primary request form, but direct exposure and L4/TCP proxies remain affected, and netty.fileServerEnabled is enabled by default. This issue is fixed in 5.7.12.
Title GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
Weaknesses CWE-200
CWE-22
CWE-522
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Gravitlauncher Launcher
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:33:25.740Z

Reserved: 2026-06-15T20:07:02.184Z

Link: CVE-2026-54617

cve-icon Vulnrichment

Updated: 2026-09-18T17:32:36.862Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:51.003

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-522

    Insufficiently Protected Credentials