Impact
The vulnerability allows an attacker to trigger a race condition during client disconnection that causes the server to execute multiple death handlers. Each death handler causes the player's inventory items and experience to be dropped and subsequently re‑added, resulting in duplicate items and XP. The weakness is categorized as CWE‑664, an improper synchronization issue.
Affected Systems
All PocketMine‑MP installations running versions earlier than 5.39.2 are affected. This includes any server instance deployed by the pmmp community and any version before the 5.39.2 release on the official repository.
Risk and Exploitability
The CVSS score is 6.3, representing medium impact. No EPSS value is supplied, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Based on the description, it is inferred that the attack requires an attacker to control a client that connects to the server and send crafted packets during a disconnect event. Based on the description, it is inferred that given the symmetry of the attack vector, it can be performed over the public internet if the server allows arbitrary connections. Once triggered, the server will duplicate items and XP for the victim player without requiring administrator privileges.
OpenCVE Enrichment