GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in components/launchserver/src/main/java/pro/gravit/launchserver/socket/handlers/fileserver/FileServerHandler.java strips the first request-target character and resolves the remaining path against updatesDir without re-normalizing and verifying containment. This leaves parent-directory components in a no-leading-slash request and allows reading any file accessible to the LaunchServer process, including .keys/ecdsa_id, .keys/legacySalt, and LaunchServer.json. Disclosure of those files can expose signing keys, refresh-token material, and database credentials, enabling forged administrative access tokens and full authentication bypass. A normalizing L7 proxy may block the primary request form, but direct exposure and L4/TCP proxies remain affected, and netty.fileServerEnabled is enabled by default. This issue is fixed in 5.7.12.
CVE-2026-54617
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2026-07-02. a secondary CVSS source baseline 9.8; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EG Risk
- 59(Track)EG Risk 59/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation1% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 1%
- EPSS %ILE
- 51%
- KEV
- Not listed
Published
July 2, 2026
Last Modified
September 18, 2026
Advisory Details (3)
Auto-updated Sep 18, 2026Unauthenticated path traversal in LaunchServer FileServerHandler · Advisory · GravitLauncher/Launcher · GitHub
https://github.com/GravitLauncher/Launcher/security/advisories/GHSA-5g75-477j-2c2fGravitLauncher v5.7.12
Patch available: GravitLauncher/Launcher v5.7.12
https://github.com/GravitLauncher/Launcher/releases/tag/v5.7.12commit 8114a1d4cfbc (GravitLauncher/Launcher)
Fix landed in GravitLauncher/Launcher commit 8114a1d4cfbc — awaiting tagged release
https://github.com/GravitLauncher/Launcher/commit/8114a1d4cfbcaab4c1c337d921597805d71dee3bVendor Advisories for CVE-2026-54617(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(1)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| maven | pro.gravit.launcher:launchserver-api | — | ghsa |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| pro.gravit.launcher:launchserver-api | 5.0.10 ... 5.6.9 (43 versions) | — | — |
Weakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 16× in last 7d / 49× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 270 total refreshes for this CVE.
- 2026-09-18 19:30 UTCEG score recompute
- 2026-09-18 19:30 UTCGHSA enrichment
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-18 18:44 UTCEG score recompute
- 2026-09-18 18:44 UTCGHSA enrichment
- 2026-09-18 10:50 UTCGHSA enrichment
- 2026-09-18 06:14 UTCGHSA enrichment
- 2026-09-17 19:28 UTCEG score recompute
- 2026-09-17 19:28 UTCGHSA enrichment
- 2026-09-17 18:54 UTCGHSA enrichment
- 2026-09-14 08:50 UTCGHSA enrichment
- 2026-09-14 04:33 UTCGHSA enrichment
- 2026-09-14 00:15 UTCGHSA enrichment
- 2026-09-13 17:43 UTCGHSA enrichment
- 2026-09-13 13:16 UTCGHSA enrichment
- 2026-09-13 08:59 UTCGHSA enrichment
- 2026-09-12 14:15 UTCGHSA enrichment
- 2026-09-06 14:19 UTCGHSA enrichment
- 2026-09-06 04:54 UTCGHSA enrichment
- 2026-09-05 23:51 UTCGHSA enrichment
- 2026-08-31 01:28 UTCGHSA enrichment
- 2026-08-30 21:09 UTCGHSA enrichment
- 2026-08-30 16:51 UTCGHSA enrichment
- 2026-08-30 11:22 UTCGHSA enrichment
- 2026-08-28 02:46 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-08-27 22:14 UTCGHSA enrichment
- 2026-08-25 13:42 UTCGHSA enrichment
- 2026-08-25 05:30 UTCGHSA enrichment
- 2026-08-25 01:12 UTCGHSA enrichment
- 2026-08-24 20:55 UTCGHSA enrichment
- 2026-08-24 14:32 UTCGHSA enrichment
- 2026-08-24 10:15 UTCGHSA enrichment
- 2026-08-24 05:46 UTCGHSA enrichment
- 2026-08-24 01:28 UTCGHSA enrichment
- 2026-08-23 21:11 UTCGHSA enrichment
- 2026-08-23 16:53 UTCGHSA enrichment
- 2026-08-23 12:36 UTCGHSA enrichment
- 2026-08-23 08:19 UTCGHSA enrichment
- 2026-08-23 04:01 UTCGHSA enrichment
- 2026-08-22 23:42 UTCGHSA enrichment
- 2026-08-22 19:24 UTCGHSA enrichment
- 2026-08-22 15:04 UTCGHSA enrichment
- 2026-08-22 10:45 UTCGHSA enrichment
- 2026-08-22 06:26 UTCGHSA enrichment
- 2026-08-21 23:08 UTCGHSA enrichment
- 2026-08-21 18:46 UTCGHSA enrichment
- 2026-08-21 14:27 UTCGHSA enrichment
- 2026-08-21 10:07 UTCGHSA enrichment
- 2026-08-21 05:49 UTCGHSA enrichment
- 2026-08-21 01:31 UTCGHSA enrichment
- 2026-08-20 21:14 UTCGHSA enrichment
- 2026-08-20 16:57 UTCGHSA enrichment
- 2026-08-20 12:40 UTCGHSA enrichment
- 2026-08-20 08:21 UTCGHSA enrichment
- 2026-08-20 04:01 UTCGHSA enrichment
- 2026-08-19 14:10 UTCGHSA enrichment
- 2026-08-19 09:51 UTCGHSA enrichment
- 2026-08-19 05:30 UTCGHSA enrichment
- 2026-08-19 01:12 UTCGHSA enrichment
- 2026-08-18 20:54 UTCGHSA enrichment
- 2026-08-18 11:47 UTCGHSA enrichment
- 2026-08-18 04:29 UTCGHSA enrichment
- 2026-08-17 22:50 UTCGHSA enrichment
- 2026-08-17 17:13 UTCGHSA enrichment
- 2026-08-17 12:53 UTCGHSA enrichment
- 2026-08-17 08:35 UTCGHSA enrichment
- 2026-08-17 04:18 UTCGHSA enrichment
- 2026-08-17 00:01 UTCGHSA enrichment
- 2026-08-16 19:43 UTCGHSA enrichment
- 2026-08-16 14:44 UTCGHSA enrichment
- 2026-08-16 10:26 UTCGHSA enrichment
- 2026-08-16 06:09 UTCGHSA enrichment
- 2026-08-16 01:52 UTCGHSA enrichment
- 2026-08-15 21:34 UTCGHSA enrichment
- 2026-08-15 17:16 UTCGHSA enrichment
- 2026-08-15 12:59 UTCGHSA enrichment
- 2026-08-15 08:42 UTCGHSA enrichment
- 2026-08-15 04:24 UTCGHSA enrichment
- 2026-08-15 00:05 UTCGHSA enrichment
- 2026-08-14 19:48 UTCGHSA enrichment
- 2026-08-14 15:31 UTCGHSA enrichment
- 2026-08-14 11:14 UTCGHSA enrichment
- 2026-08-14 06:57 UTCGHSA enrichment
- 2026-08-14 02:39 UTCGHSA enrichment
- 2026-08-13 22:22 UTCGHSA enrichment
- 2026-08-13 18:04 UTCGHSA enrichment
- 2026-08-13 13:44 UTCGHSA enrichment
- 2026-08-13 09:20 UTCGHSA enrichment
- 2026-08-13 05:02 UTCGHSA enrichment
- 2026-08-13 00:45 UTCGHSA enrichment
- 2026-08-12 20:28 UTCGHSA enrichment
- 2026-08-12 16:11 UTCGHSA enrichment
- 2026-08-12 11:54 UTCGHSA enrichment
- 2026-08-12 07:36 UTCGHSA enrichment
- 2026-08-12 03:19 UTCGHSA enrichment
- 2026-08-11 23:01 UTCGHSA enrichment
- 2026-08-11 18:43 UTCGHSA enrichment
- 2026-08-11 14:26 UTCGHSA enrichment
- 2026-08-11 10:08 UTCGHSA enrichment
- 2026-08-11 05:50 UTCGHSA enrichment
Related CVEs(same CWE)
Same CWE
10 shownCWE-200 · CWE-22 · CWE-522
- CVE-2026-92960EG 10.0CRITICAL
- CVE-2026-92947EG 10.0CRITICAL
- CVE-2026-85706EG 10.0 KEVEPSS p96CRITICAL
- CVE-2026-7312NVD 7.5EG 10.0CRITICAL
- CVE-2026-42869EG 10.0CRITICAL
- CVE-2026-29128EG 10.0CRITICAL
- CVE-2026-20234EG 9.9CRITICAL
- CVE-2026-86464EG 9.9CRITICAL
- CVE-2026-82954EG 9.9CRITICAL
- CVE-2026-20359EG 9.9CRITICAL
Frequently asked(5)
What is CVE-2026-54617?
When was CVE-2026-54617 disclosed?
Is CVE-2026-54617 actively exploited?
What is the CVSS score of CVE-2026-54617?
How do I remediate CVE-2026-54617?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-54617
Is Your Infrastructure Affected by CVE-2026-54617?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.