CVE-2025-31488

Source
https://cve.org/CVERecord?id=CVE-2025-31488
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31488.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-31488
Aliases
  • GHSA-wfpw-hfcp-9m73
Published
2025-04-06T19:56:24.648Z
Modified
2026-04-10T05:26:04.887748Z
Severity
  • 5.0 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
Plain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowser
Details

Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access the specified webpage without knowing it. This vulnerability is fixed in 2.9.3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/31xxx/CVE-2025-31488.json"
}
References

Affected packages

Git / github.com/hex-dragon/pcl2

Affected ranges

Type
GIT
Repo
https://github.com/hex-dragon/pcl2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.9.3"
        }
    ]
}

Affected versions

2.*
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.1
2.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31488.json"