tag
Minecraft
CVE-2025-14700
web
CRITICAL 9.9
Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
Crafty Controller's server Webhook configuration accepts a user-controlled "body" template that is rendered server-side with Jinja2 without sandboxing. An authenticated user can set the webhook body to a Jinja2 expression that escapes the sandbox via…
Unverified
2026-07-06
None assigned as of 2026-07-03
binary
CRITICAL 3.1
Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
The chain begins with Lunar Client's Explore feature rendering attacker-controlled Modrinth project Markdown (project body and version changelog) through ReactMarkdown with the rehypeRaw plugin and no observed HTML sanitizer, allowing raw HTML/script-capable…
Unverified
2026-07-03