Skip to content

Path traversal with mrpack files

High
RyanTheAllmighty published GHSA-7cff-8xv4-mvx6 Feb 4, 2023

Package

https://github.com/ATLauncher/ATLauncher (Software)

Affected versions

<= 3.4.26.0

Patched versions

3.4.27.0

Description

Impact

When manually importing a .mrpack file, path traversal was possible, and files could be downloaded by the launcher into places outside it's own directory using a specially crafted path string in the modrinth.index.json within the .mrpack file.

Patches

Upgrade to version 3.4.27.0 (the launcher auto updates itself as long as you're not using AUR or Flatpak)

Workarounds

Do not install any .mrpack modpack manually. Modpacks installed through the launchers Modrinth pack browser are safe.

References

https://docs.modrinth.com/docs/modpacks/format_definition/#files

Severity

High
7.8
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-25303

Weaknesses

Credits