Executive brief
Minosoft is an open-source tool used to connect to Minecraft servers. A security flaw in how it handles encrypted communications could allow a malicious actor to recover the secret encryption keys used during a session. If successful, this could allow an attacker to intercept or tamper with the data exchanged between the user and the server.
Technical details
The vulnerability exists in the CryptManager.kt component of Minosoft, where the AES cipher is initialized using an Initialization Vector (IV) that is identical to the secret key (IvParameterSpec(key.encoded)). This violates cryptographic best practices requiring IVs to be random and unpredictable. An attacker capable of submitting specific messages for encryption can exploit this predictable IV to recover the secret key through chosen-ciphertext (CCA) or chosen-plaintext (CPA) attacks. The issue affects all versions supporting Minecraft protocol 1.7 and later, starting with commit f1ae30e. As of the advisory date, no patch or workaround is available.
Affected products
- Bixilon Minosoft 1.7 and later; starting from commit f1ae30e2b046a490026a8413b075685deb795122
Timeline
- 2026-06-18: advisory: GitHub Security Advisory published
- 2026-07-07: disclosed: NVD publication date