CVE-2025-27107

Severity CVSS v4.0:
HIGH
Type:
CWE-74 Injection
Publication date:
13/03/2025
Last modified:
13/03/2025

Description

Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 may be vulnerable to arbitrary code execution. By using Java reflection on a thrown exception object it&amp;#39;s possible to escape the JavaScript sandbox for IntegratedScripting&amp;#39;s Variable Cards, and leverage that to construct arbitrary Java classes and invoke arbitrary Java methods.<br /> This vulnerability allows for execution of arbitrary Java methods, and by extension arbitrary native code e.g. from `java.lang.Runtime.exec`, on the Minecraft server by any player with the ability to create and use an IntegratedScripting Variable Card. Versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 fix the issue.