Skip to content

Conversation

@alvarilloo
Copy link

This commit fixes a security exploit where the server-side event cd_easytime:StartTsunamiCountdown could be triggered by clients. The event was registered in a way that allowed cheaters to invoke it directly, enabling them to start tsunami mode without authorization. The fix restricts the event to trusted server-side execution.

(I accidentally deleted the previous pull request)

alvarilloo and others added 3 commits January 18, 2026 20:48
This commit fixes a security exploit where the server-side event `cd_easytime:StartTsunamiCountdown` could be triggered by clients.  The event was registered in a way that allowed cheaters to invoke it directly, enabling them to start tsunami mode without authorization.  The fix restricts the event to trusted server-side execution.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant