Skip to content

Security: MSK-Scripts/msk_enginetoggle

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest released version of MSK EngineToggle. Please make sure you are running the most recent release before reporting an issue.

Version Supported
Latest release Yes
Older versions No

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or the Discord public channels. Exploits in a FiveM resource can be abused on live servers as soon as they are public.

Instead, report them privately using one of these channels:

When reporting, please include as much of the following as you can:

  • A description of the vulnerability and its impact
  • Steps to reproduce, or a proof of concept
  • The affected version of msk_enginetoggle
  • Your setup: framework (ESX or QBCore), msk_core version, and the vehicle key script in use, if any

Events that can be triggered from the client are the most sensitive part of this resource. If you found one that is missing a distance check, an ownership check or a cooldown, that is exactly the kind of report we want.

What to Expect

  • We will acknowledge your report as soon as possible.
  • We will investigate and keep you updated on the progress.
  • Once a fix is ready, we will release it and credit you if you wish.

Please give us a reasonable amount of time to address the issue before any public disclosure. Thank you for helping keep MSK EngineToggle and its users safe.

There aren't any published security advisories