Executive brief
NamelessMC is a popular website platform used by Minecraft server owners to manage their communities. A security flaw in how the software handles social logins (OAuth) allows an attacker to force a victim to log into the attacker's account. This can lead to session swapping, where a user unintentionally performs actions or links their personal data to an account controlled by the attacker, causing confusion and potential data integrity issues.
Technical details
NamelessMC fails to validate the OAuth 'state' parameter server-side before exchanging the authorization code for an access token. The vulnerability exists in the OAuth callback handling logic within 'core/classes/Misc/NamelessOAuth.php' and 'modules/Core/pages/oauth.php'. An attacker can initiate an OAuth flow, capture their own valid callback URL, and trick a victim into navigating to it. Because the application does not verify that the state parameter matches the victim's session, it processes the attacker's authorization code, effectively logging the victim into the attacker's account. This is a classic OAuth login CSRF (session swapping) attack. The issue is resolved in version 2.2.5 by implementing proper state generation and verification.
Affected products
- NamelessMC NamelessMC <= 2.2.4
Timeline
- 2026-05-31: advisory: GitHub Security Advisory published by maintainers
- 2026-06-02: disclosed: CVE published to NVD
- 2026-06-02: patched: Fix released in version 2.2.5