Impact
The LaunchServer in GravitLauncher hosts a file server listening on port 9274 that accepts raw HTTP requests lacking a leading slash. During request processing the server strips the first character of the request‑target and resolves the remainder against the updates directory without normalizing or checking that the resolved path remains inside the intended directory. This oversight allows an unauthenticated attacker to traverse parent directories and read any file that the LaunchServer process can access, such as signing key files, token salts, and database credentials. Access to these artifacts gives an attacker the ability to forge administrative access tokens and bypass the authentication system. The flaw is a path traversal vulnerability (CWE‑22) that also results in information disclosure (CWE‑200) and credential storage weakness (CWE‑522).
Affected Systems
The vulnerability affects all releases of GravitLauncher Launcher prior to version 5.7.12. The affected component is the FileServerHandler within the LaunchServer module. No other products or versions have been identified as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 9.8 classifies this as Critical. The EPSS score of <1 % indicates a low probability of exploitation in the wild, yet the unauthenticated and remote nature of the flaw means that an attacker can exploit it from any reachable host. The weakness is not currently listed in the CISA KEV catalog. Direct exposure to the server, or exposure via port‑forwarding or L4 proxies, remains possible. Even a normalizing L7 proxy may block the primary request form, but an attacker can still send a request without a leading slash over a raw TCP connection, making mitigation largely dependent on disabling the file server or patching the software.
OpenCVE Enrichment
Github GHSA