Skip to content

MiniMessage security flaw #359

@xxwafflebotxx

Description

@xxwafflebotxx

Describe the bug

Any player can make MiniMessages, Ive been unable to find anything in regards to removing a permission/disabling the usage. All it takes is one player making a weird clickable and one very gullible person to click it and the entire server could be compromised. Theres other usages such as sending money etc for players that dont directly want to go after things such as OP.

How to reproduce

<click:run_command:'/op (INSERT PLAYER NAME HERE)'><hover:show_text:'This is a safe test'>Click me

Screenshots / Videos

Image

Server Log

No response

Filled out form correct and using latest version

I confirm

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bug: UnconfirmedThis could possibly be a bug, but it hasn't been confirmed yet.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions