CVE-2025-27107: Integrated Scripting vulnerable to arbitrary code execution via Java reflection
Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 may be vulnerable to arbitrary code execution. By using Java reflection on a thrown exception object it's possible to escape the JavaScript sandbox for IntegratedScripting's Variable Cards, and leverage that to construct arbitrary Java classes and invoke arbitrary Java methods. This vulnerability allows for execution of arbitrary Java methods, and by extension arbitrary native code e.g. from java.lang.Runtime.exec, on the Minecraft server by any player with the ability to create and use an IntegratedScripting Variable Card. Versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.21.1-1.0.17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.21.4-1.0.9-254 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.20.1-1.0.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.19.2-1.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27107?
CVE-2025-27107 has been classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-27107?
To mitigate CVE-2025-27107, update Integrated Scripting to versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, or 1.19.2-1.0.10 or later.
What type of vulnerability is CVE-2025-27107?
CVE-2025-27107 is an arbitrary code execution vulnerability affecting earlier versions of Integrated Scripting.
Who is affected by CVE-2025-27107?
Users of Integrated Scripting prior to specified versions are vulnerable to CVE-2025-27107.
Is there a workaround for CVE-2025-27107?
There are no specific workarounds for CVE-2025-27107; upgrading to a patched version is recommended.