Skip to content

Security: qbcore-fivem/txAdminRecipe

SECURITY.md

Security policy

QBCore FiveM takes vulnerabilities in official resources seriously. Help us protect server owners and players by reporting security issues privately and allowing time for coordinated investigation and remediation.

Supported versions

Security support is provided for the current default branch and the latest published release of an official QBCore repository. Older releases, forks, third-party resources, and locally modified versions may be outside the scope of support. Reports involving modifications are still useful when the same issue can be reproduced in the current official version.

Report a vulnerability privately

Use Report a vulnerability under the affected repository's Security tab to submit a private vulnerability report. Select the repository containing the affected code so the appropriate maintainers receive it.

Do not disclose vulnerability details in a public issue, pull request, discussion, Discord channel, or social-media post.

If GitHub private vulnerability reporting is not available for the affected repository, join the official QBCore Discord and ask a staff member to arrange private contact. Do not include technical details or proof-of-concept material in a public Discord channel.

Include as much of the following as possible:

  • Affected repository, version, release, or commit
  • Vulnerability description and realistic impact
  • Reproduction steps or a minimal proof of concept
  • Required permissions, configuration, and dependencies
  • Known mitigations or workarounds
  • Whether the issue is already being exploited or publicly discussed
  • Your preferred name for credit, or a request to remain anonymous
  • Any proposed disclosure timeline

Remove unrelated credentials, personal data, player identifiers, and production database contents from reports and evidence.

What to expect

  • We aim to acknowledge a new report within three business days.
  • We aim to provide an initial assessment or request for additional information within seven business days.
  • We will provide material status updates at least every fourteen days while an accepted report remains unresolved.
  • Remediation and disclosure timing will depend on severity, exploitability, affected users, fix complexity, and downstream coordination.

These are response targets, not guarantees. Volunteer availability and the complexity of an issue may affect timing. If you have not received an acknowledgement within the target period, follow up on the private report.

Coordinated disclosure

Please keep the report private until maintainers have had a reasonable opportunity to investigate, prepare a fix or mitigation, and coordinate notice to affected users. We will work with reporters toward a mutually reasonable disclosure date and will not request indefinite secrecy.

When appropriate, QBCore may publish a GitHub Security Advisory describing affected versions, impact, remediation, and credit. Reporters who request anonymity will not be named.

Out of scope

General configuration errors, unsupported versions, cheats that do not exploit a vulnerability in official QBCore code, denial-of-service testing against systems you do not own, social engineering, and reports concerning third-party resources should be directed to their respective owners or normal support channels.

There aren't any published security advisories