External risk intelligence

GravitLauncher File Server Path Traversal Leads to Credential Exposure

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-54617

The vulnerability resides in a LaunchServer file server that is enabled by default on a specific port and is designed to handle network requests for updates. While often used for gaming services, it functions as an externally reachable file server and delivery service, making public internet exposure a common deployment scenario for this type of infrastructure component.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in GravitLauncher's file server allows unauthenticated remote attackers to read sensitive files, potentially exposing signing keys, authentication tokens, and credentials. This could enable forged administrative access and complete bypass of authentication mechanisms, impacting the security of services that rely on this launcher.

  • Unauthenticated attackers can access sensitive files remotely.
  • Compromised credentials could allow forged administrative access.
  • Confirm relevance and exposure of this launcher's services.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can send specially crafted HTTP requests to the GravitLauncher's file server. The server mishandles requests that lack a leading slash, allowing the attacker to read sensitive files from the server's file system. This could expose private keys, authentication tokens, or database credentials, potentially leading to forged administrative access and complete authentication bypass.

  • No authentication required.
  • Triggered by unnormalized file path requests.
  • Risk of credential exposure and auth bypass.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote actor could read sensitive files from the GravitLauncher server when a specific file server is enabled and accessible. This could expose signing keys, refresh tokens, and database credentials.

  • Sensitive file access.
  • Unauthenticated HTTP requests.
  • Forged administrative access tokens.

Operational Fix

Recommended remediation, mitigation, and detection steps

The GravitLauncher's file server is likely managed by the application or platform team responsible for its deployment and operation. The first practical step is to identify all instances of the GravitLauncher, confirm if the file server on port 9274 is exposed externally and accessible, and determine if it is business-critical. Once identified and assessed, an accountable owner should be assigned to plan remediation, prioritizing instances with the highest risk.

  • Application or platform teams own the issue.
  • Verify external exposure and reachability first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GravitLauncher?

GravitLauncher is an open-source Minecraft launcher based on the sashok724 v3 platform. It includes a LaunchServer component that acts as a file server to distribute updates to client applications. Because it manages game assets and authentication data, this server handles sensitive information and is intended to be reachable by client installations.

What is the vulnerability in CVE-2026-54617?

This vulnerability is a Path Traversal, classified as CWE-22. The file server incorrectly processes HTTP requests that lack a leading slash. Instead of blocking these invalid paths, the software strips the first character and attempts to serve files from outside the intended directory. This allows an attacker to bypass file restrictions and read system files.

How does an attacker trigger this file access?

An attacker sends a specially crafted HTTP request to the file server on port 9274 without a leading slash. This triggers the flaw in the path resolution logic. It is important to note that standardizing requests through a layer-7 proxy might block this specific format, but the vulnerability remains active if the server is exposed directly or via layer-4 TCP proxies.

Is my GravitLauncher installation at risk?

Your risk depends on network accessibility. Halo Surface Signal identifies this component as a file server that is enabled by default, often deployed in internet-facing configurations to serve game updates. If your instance is reachable from the public internet, it is at higher risk for unauthorized file access compared to those restricted to internal networks.

How do I secure my environment against this?

The most effective response is to update your software to version 5.7.12 or later, which contains the fix. Before updating, identify all running instances of the LaunchServer. Confirm which are exposed to the internet, prioritize those for patching, and verify that the file server functionality is necessary for your current operations.

References