CVE-2023-29478: Bibliocraftmod Bibliocraft
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.
Affected products
- Bibliocraftmod Bibliocraft: before 2.4.6 (fixed in 2.4.6)
Published 2023-04-07. Last modified 2026-06-17.