CVE-2025-31488 - CVE House
Back to Database
Status published Medium CVE-2025-31488

Plain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowser

Vulnerability Description

Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access the specified webpage without knowing it. This vulnerability is fixed in 2.9.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31488

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

PCL2
Vulnerable Versions:
< 2.9.3

Timeline

Official Publish: April 6th, 2025
Last Modified: April 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)