Local Authentication Vulnerability in XianYuLauncher for Minecraft Java Edition
CVE-2026-48991

5.5MEDIUM

Key Information:

Vendor
CVE Published:
17 June 2026

What is CVE-2026-48991?

XianYuLauncher, a popular Minecraft Java Edition launcher, has a vulnerability that exposes sensitive authentication data during user login. This occurs under specific local attack conditions, particularly when attackers can intercept or manipulate the local authentication flow on the same device. Previous versions prior to 1.5.5 utilized a fixed localhost redirect URI that lacked essential PKCE and state validation features, increasing the risk of exploitation. The issue has been addressed in version 1.5.5, making it crucial for users to update to secure their authentication process.

Affected Version(s)

XianYuLauncher < 1.5.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.