CVE-2023-29478: Bibliocraftmod Bibliocraft

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

Affected products

Published 2023-04-07. Last modified 2026-06-17.