SilkMC / silk-compose

Bringing Kotlin Compose UI to Minecraft
https://silkmc.net/silk-compose/docs/
GNU Affero General Public License v3.0
67 stars 5 forks source link

Security Concern: RCE #3

Closed Xyndra closed 2 months ago

Xyndra commented 2 months ago

Could you please clarify how this is not straight-up RCE

r0yzer commented 2 months ago

true.

jakobkmar commented 2 months ago

Could you please clarify how it is?

Xyndra commented 2 months ago

kennt ihr das wenn ihr gin tee trinkt und dann erstmal backflip macht

bro wie hart betrunken kann man denn bitte sein. das ist die falsche sprache und eine professionelle platform was zur hölle ist deine mission

Xyndra commented 2 months ago

Could you please clarify how it is?

image This is for Serverplayer and Compose is code so basically you are running remote code

kxmpxtxnt commented 2 months ago

Doesn't it just create the image on cards? Nothing is done on the client side

Xyndra commented 2 months ago

I am not sure that is why I opened this issue, since it is not really clarified. It would suprise me if it just created and sended images since there was talk about animations and stuff

jakobkmar commented 2 months ago

This is for Serverplayer and Compose is code so basically you are running remote code

no, the server renders compose and sends the resulting changed pixels to the client

jakobkmar commented 2 months ago

It would suprise me if it just created and sended images since there was talk about animations and stuff

that is exactly what happens, and animations are entirely possible, since the server can send a pixel change set

Xyndra commented 2 months ago

It would suprise me if it just created and sended images since there was talk about animations and stuff

that is exactly what happens, and animations are entirely possible, since the server can send a pixel change set Oh okay, I just wasn't sure since it didn't seem clear to me