Junglewise Threat Intelligence

CVE-2024-56141: Bixilon Minosoft predictable IV in CryptManager encryption routine

CVE-2024-56141 · Severity: medium · CVSS 5 · Published 2026-07-07

Executive brief

Minosoft is an open-source tool used to connect to Minecraft servers. A security flaw in how it handles encrypted communications could allow a malicious actor to recover the secret encryption keys used during a session. If successful, this could allow an attacker to intercept or tamper with the data exchanged between the user and the server.

Technical details

The vulnerability exists in the CryptManager.kt component of Minosoft, where the AES cipher is initialized using an Initialization Vector (IV) that is identical to the secret key (IvParameterSpec(key.encoded)). This violates cryptographic best practices requiring IVs to be random and unpredictable. An attacker capable of submitting specific messages for encryption can exploit this predictable IV to recover the secret key through chosen-ciphertext (CCA) or chosen-plaintext (CPA) attacks. The issue affects all versions supporting Minecraft protocol 1.7 and later, starting with commit f1ae30e. As of the advisory date, no patch or workaround is available.

Affected products

  • Bixilon Minosoft 1.7 and later; starting from commit f1ae30e2b046a490026a8413b075685deb795122

Timeline

  • 2026-06-18: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: NVD publication date

References