Unauthenticated Path Traversal in GravitLauncher FileServerHandler – Arbitrary File Read & Authentication Bypass
An unauthenticated path traversal in LaunchServer's HTTP file server allows remote attackers to read arbitrary files, including cryptographic signing keys and database credentials, enabling full authentication bypass and system compromise. This affects GravitLauncher ≤ 5.7.11 on default port 9274.