Many of our projects run on live game servers, so please do not open a public issue for security problems (server crash exploits, remote code execution, SQL injection, admin bypass, leaked credentials...).
Instead, report it privately:
- Go to the affected repository.
- Open the Security tab and click Report a vulnerability.
- Describe the issue, the affected version and, if possible, how to reproduce it.
If you can't use GitHub's private reporting, contact a maintainer on our Discord and ask for a private channel. Don't post details in public channels.
- We'll acknowledge your report as soon as we can, usually within a few days.
- We'll keep you updated while we work on a fix, and credit you in the advisory unless you prefer to stay anonymous.
- Please give us reasonable time to release a fix before disclosing the issue publicly.
Only the latest release (or the master/main branch) of each project receives security fixes.
Some repositories are forks (SourceMod, Metamod:Source, SDKs, third-party plugins). If the issue also affects the upstream project, please report it to them as well.