Mojira Archive
MC-276888

Container lock code leaked through held item custom_name to then copy and use via anvil

This is not a feature request; it is a serious security issue. I previously reported this problem in MC-276865, but the official response deemed it invalid and categorized it as a feature request. Let me be clear: this is not a feature request. The vulnerability relates to the minecraft:lock component and its reliance on minecraft:customname. The key's customname being easily known allows malicious players to rename their items with an anvil, impersonating the real key and potentially stealing items from chests. This poses a direct threat to player property and undermines the integrity of the game. Again, this is not a feature request; it is a critical security concern. I recommend implementing a more concealed component (e.g., minecraft:password) to protect players' items from theft.

Fixed

Tan_Jansheng

2024-09-21, 01:49 AM

2024-11-18, 10:03 AM

2024-11-18, 10:03 AM

2

2

Plausible

Low

Platform

Inventory, Items, Networking

1.21.1, 24w38a

24w39a