A security vulnerability has been identified in the PixelReel mod for Minecraft, specifically in version pixelreel-1.0.0.jar and the 26.3 snapshots on CurseForge. This flaw exposes media server URLs and API keys to other players on the same multiplayer server. The mod requires users to process streams through VLC, which leads to the extraction and transmission of sensitive authentication details to Minecraft. The developer has admitted that the mod was created without a thorough security review. Users are advised to create a read-only account for use with PixelReel and to remove the mod from multiplayer environments. It is recommended that all exposed API keys be rotated, as no patch has been released to fix the vulnerability.