PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2022-51009 affects PocketMine-MP, a popular Minecraft server software, through improper exception handling in the adhocore/json-comment library when processing skin geometry data. When attackers send specially crafted login or skin packets containing invalid JSON geometry, the server fails to catch the resulting RuntimeException, triggering an immediate crash. This denial-of-service vulnerability impacts game server administrators and their player communities, as attackers can repeatedly crash servers with minimal effort by sending malformed packets. The low barrier to exploitation—no authentication required, simple packet manipulation—makes this a practical threat to public and private Minecraft servers.
While this CVE lacks direct MITRE ATT&CK mapping, Casky's Claude-powered analysis would detect the attack vectors through exception-handling weakness patterns and resource exhaustion reconnaissance. Practitioners using Casky would observe findings related to Input Validation failures (CWE-248) and Denial of Service attack chains—specifically identifying how unauthenticated network packets bypass defensive layers. The platform's 754 mapped security skills would correlate this pattern with techniques like Resource Exhaustion and identify it as a pre-exploitation reconnaissance opportunity where attackers probe server stability. Practitioners would see alerts on unhandled exception patterns in game protocol handlers, enabling them to patch, implement input validation middleware, or rate-limit geometry parsing before malicious actors weaponize the crash.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2022-51009. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation