NamelessMC Sensitive Information Disclosure Vulnerability

Vulnerability

A sensitive information disclosure vulnerability has been identified in NamelessMC versions through 2.2.3. This issue allows unauthenticated remote attackers to access sensitive data, such as the absolute path of the source code, by exploiting the member list query parameter. The vulnerability arises because the application does not properly manage error responses, enabling attackers to craft requests that trigger errors revealing confidential server information. This vulnerability can be exploited without authentication.

Impact

Exploitation of this vulnerability leads to the unauthorized disclosure of sensitive information, including server paths, which could facilitate further attacks.

Reproduction

To reproduce this vulnerability, send a GET request to the member list query with an empty list parameter. The server will respond with a 200 OK status, but the content will include an error message disclosing the absolute path of the source code, along with details about the error's origin, such as the file name and line number.

Remediation

Users are advised to update to NamelessMC version 2.2.4 or later, where this vulnerability has been patched.

Added: Aug 18, 2025, 4:17 PM
Updated: Aug 18, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
9.7
remediation
7.7
relevance
0.4
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.