Crafatar is a niche avatar-rendering service for the Minecraft ecosystem, operating a focused product footprint around avatar image generation and delivery. The observed vulnerability signal centers on path-traversal weaknesses, reflecting input-validation demands inherent to a file-serving application; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crafatar over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24756HIGH Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances runni | Feb 1, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crafatar.
Media articles that mention a CVE ID that affects a product developed by Crafatar — matched by CVE ID, not by vendor name.