Executive brief
XianYuLauncher is a third-party launcher for Minecraft Java Edition. A security flaw in its login process could allow an attacker with access to a user's computer to intercept sensitive Microsoft account login information. This could lead to unauthorized access to the user's Minecraft or Microsoft account if they attempt to sign in while an attacker is monitoring the device.
Technical details
A vulnerability exists in the legacy Microsoft account OAuth sign-in flow of XianYuLauncher due to the use of a fixed localhost redirect URI (http://localhost:8080/) without PKCE (Proof Key for Code Exchange) or state validation. An attacker with local access to the victim's machine could intercept the authorization code or sensitive authentication artifacts during a user-initiated login. This is primarily achieved by observing or interfering with the local network traffic or the browser-to-app redirect flow. The issue has been resolved in version 1.5.5 by migrating to the Microsoft Authentication Library (MSAL), implementing hardened interactive sign-in handling, and improving token persistence security.
Affected products
- XianYuLauncher XianYuLauncher < 1.5.5
Timeline
- 2026-05-17: patched: Fix merged in Pull Request #213
- 2026-05-24: advisory: GitHub Security Advisory published
- 2026-06-17: disclosed: CVE published to NVD