PocketMine-MP vulnerability

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

Published 6 Sep 2026Updated 6 Sep 20263 sources
CVSS 8.7

Source timeline

CVE record published by NVDView source ↗