PolyMC is a launcher for the Minecraft game client that enables custom modded instances and community-driven gameplay configuration. The documented vulnerability profile centers on path-traversal weaknesses in the launcher's handling of file operations, reflecting the risks inherent in executing user-supplied or third-party mod configurations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polymc over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25305HIGH PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory. | Apr 4, 2023 | 7.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polymc.
Media articles that mention a CVE ID that affects a product developed by Polymc — matched by CVE ID, not by vendor name.