Unknown · Xianyulauncher · CVE-2026-48991
**Name of the Vulnerable Software and Affected Versions**
XianYuLauncher versions prior to 1.5.5
**Description**
Sensitive authentication artifacts may be exposed during a user-initiated login when certain local attack conditions are met. The issue stems from the legacy Microsoft account OAuth sign-in flow, which utilizes a fixed localhost redirect URI and lacks Proof Key for Code Exchange (PKCE)—a security extension that prevents authorization code injection—and state validation, which is used to prevent cross-site request forgery. Exploitation is most likely if an attacker can observe, intercept, or interfere with the local authentication flow on the same device.
**Recommendations**
Update to version 1.5.5.