PT-2026-86775 · Pmmp+2 · Pocketmine-Mp+1

·

CVE-2022-51013

·

Published

2022-03-18

·

Updated

2026-09-07

CVSS v3.1
CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Impact

Due to a workaround applied in 1.13, an attacker may send a negative damage/meta value in a tool or armour item's NBT, which TypeConverter then blindly uses as if it was valid without being checked.
When this invalid metadata value reaches Durable->setDamage(), an exception is thrown because the metadata is not within the expected range for damage values.
This can be reproduced with either a too-large damage value, or a negative one.

Patches

c8e1cfcbee4945fd4b63d2a7e96025c59744d4f1

Workarounds

In theory this can be checked by plugins using a custom TypeConverter, but this is likely to be very cumbersome.

For more information

Exploit

Fix

Incorrect Type Conversion or Cast

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-51013
GHSA-46C5-PFJ8-FV65

Affected Products

Pocketmine-Mp
Pocketmine/Pocketmine-Mp