PT-2025-11212 · Unknown+1 · Integrated Scripting+1

Chc4

·

Published

2025-03-13

·

Updated

2025-03-15

·

CVE-2025-27107

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Integrated Scripting versions prior to 1.21.1-1.0.17 Integrated Scripting versions prior to 1.21.4-1.0.9-254 Integrated Scripting versions prior to 1.20.1-1.0.13 Integrated Scripting versions prior to 1.19.2-1.0.10
Description: The issue allows for arbitrary code execution by using Java reflection on a thrown exception object to escape the JavaScript sandbox for IntegratedScripting's Variable Cards. This enables the construction of arbitrary Java classes and invocation of arbitrary Java methods, including execution of arbitrary native code, for example, from java.lang.Runtime.exec, on the Minecraft server by any player with the ability to create and use an IntegratedScripting Variable Card.
Recommendations: Update to version 1.21.1-1.0.17 or later to resolve the issue. Update to version 1.21.4-1.0.9-254 or later to resolve the issue. Update to version 1.20.1-1.0.13 or later to resolve the issue. Update to version 1.19.2-1.0.10 or later to resolve the issue.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27107
GHSA-2V5X-4823-HQ77

Affected Products

Integrated Scripting
Minecraft