PatchSiren cyber security CVE debrief
CVE-2026-48991 XianYuLauncher CVE debrief
The XianYuLauncher, a Minecraft Java Edition launcher, had a vulnerability in versions prior to 1.5.5. This issue allowed sensitive authentication artifacts to be exposed during a user-initiated login under specific local attack conditions. The vulnerability was caused by a fixed localhost redirect URI without PKCE or state validation. The exploitation of this vulnerability is most likely to occur when an attacker can observe, intercept, or interfere with the local authentication flow on the same device. This issue has been addressed in version 1.5.5. Users should update to the latest version to mitigate this vulnerability.
- Vendor
- XianYuLauncher
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-22
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-22
Who should care
Users of XianYuLauncher, especially those handling sensitive authentication information, should be aware of this vulnerability. Updating to version 1.5.5 or later is recommended to prevent potential exposure of sensitive authentication artifacts.
Technical summary
The XianYuLauncher vulnerability (CVE-2026-48991) arises from its reliance on a fixed localhost redirect URI without implementing Proof Key for Code Exchange (PKCE) or state validation. This oversight allows for the potential exposure of sensitive authentication artifacts during the login process under certain local attack conditions. The CVSS score for this vulnerability is 5.5, indicating a medium severity level. The vulnerability has been fixed in version 1.5.5 of the launcher.
Defensive priority
Medium
Recommended defensive actions
- Update XianYuLauncher to version 1.5.5 or later.
- Use secure authentication practices, including implementing PKCE and state validation for authentication flows.
- Monitor local network traffic for potential interception attempts.
- Ensure that the launcher is used in a secure environment, protected from local attacks.
- Regularly review and update software dependencies to ensure the latest security patches are applied.
- Consider using additional security measures, such as two-factor authentication, to enhance login security.
Evidence notes
The information provided is based on the CVE record and NVD details for CVE-2026-48991. The vulnerability was published on June 17, 2026, and modified on June 18, 2026. References to the fix in version 1.5.5 and details about the vulnerability can be found in the GitHub pull request and security advisory.
Official resources
public