Local Authentication Vulnerability in XianYuLauncher for Minecraft Java Edition
CVE-2026-48991
5.5MEDIUM
What is CVE-2026-48991?
XianYuLauncher, a popular Minecraft Java Edition launcher, has a vulnerability that exposes sensitive authentication data during user login. This occurs under specific local attack conditions, particularly when attackers can intercept or manipulate the local authentication flow on the same device. Previous versions prior to 1.5.5 utilized a fixed localhost redirect URI that lacked essential PKCE and state validation features, increasing the risk of exploitation. The issue has been addressed in version 1.5.5, making it crucial for users to update to secure their authentication process.
Affected Version(s)
XianYuLauncher < 1.5.5
