The Cfx team takes the security of our software products and services seriously. This includes the products built from this repository (FiveM, RedM, FXServer), along with our other games, products, and online services.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Report security issues privately through responsible disclosure so they can be addressed before becoming public. Public reporting increases risk for our community and its players: public reports will be deleted on first instance, and repeat offenders may be banned from our GitHub organization.
Instead, please submit your report to our HackerOne report form.
Valid reports may be eligible for a bounty. Thanks for helping keep the platform and its community safe.