Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch command injection from entity inputs #187

Open
ThisAMJ opened this issue Jul 13, 2023 · 0 comments
Open

Patch command injection from entity inputs #187

ThisAMJ opened this issue Jul 13, 2023 · 0 comments
Labels
game bugfix Request to fix a bug in the game itself

Comments

@ThisAMJ
Copy link
Member

ThisAMJ commented Jul 13, 2023

A malicious map could potentially execute arbitrary commands as the player, such as unbindall and other such shenanigans. This has been somewhat addressed by ReloadedFix, but more commands should be blacklisted / swap to a whitelist / another solution, and it should apply universally.

@ThisAMJ ThisAMJ added the game bugfix Request to fix a bug in the game itself label Jul 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
game bugfix Request to fix a bug in the game itself
Projects
None yet
Development

No branches or pull requests

1 participant