Vulnerability DatabaseGHSA-h87r-f4vc-mchv

GHSA-h87r-f4vc-mchv
PHP vulnerability analysis and mitigation

Overview

A high-severity vulnerability (GHSA-h87r-f4vc-mchv) was discovered in PocketMine-MP versions prior to 4.18.1, affecting the network handling of inventories. The vulnerability was discovered and disclosed on May 30, 2023, and was patched in version 4.18.1. The issue allowed players to request dropping more items than they had available in their hotbar, which could lead to server crashes (GitHub Advisory).

Technical details

The vulnerability was introduced in version 4.18.0 during a complete revamp of the network handling of inventories. It has a CVSS v3.1 score of 7.5 (High), with base metrics indicating Network attack vector, Low attack complexity, No privileges required, No user interaction needed, Unchanged scope, No impact on confidentiality and integrity, but High impact on availability. The technical vulnerability exists in the inventory transaction handling system where the server failed to properly validate the quantity of items being dropped against the available inventory (GitHub Advisory).

Impact

The primary impact of this vulnerability was the ability to crash the server through improper item dropping requests. While the vulnerability did not lead to any item duplication issues, it was reported to have been exploited in the wild, causing service disruptions for affected servers (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 4.18.1 through commit 58974765a68f63a9968a7ff3a06f584ff2ee08d2. While a workaround exists by handling InventoryTransactionPacket in DataPacketReceiveEvent and verifying item count drops, it is not recommended due to implementation complexity. The recommended solution is to upgrade to version 4.18.1 or later (PocketMine Changelog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65346CRITICAL9.1
  • PHPPHP
  • alexusmai/laravel-file-manager
NoNoDec 04, 2025
CVE-2025-66468HIGH7.6
  • PHPPHP
  • aimeos/ai-cms-grapesjs
NoYesDec 02, 2025
CVE-2025-65345MEDIUM6.5
  • PHPPHP
  • alexusmai/laravel-file-manager
NoNoDec 03, 2025
CVE-2025-65657MEDIUM6.5
  • PHPPHP
  • feehi/cms
NoNoDec 02, 2025
CVE-2025-65186MEDIUM6.1
  • PHPPHP
  • getgrav/grav
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management