Engine exploit allows bad actors to load scripts in character assets to achieve serverside execution

This is quite sensitive, I’d rather explain in the private section below.

A private message is associated with this bug report

11 Likes

Hey,

We resolved this issue in private communication a while ago but wanted to post here to mention that we have completed rolling out a change to the default AssetTypeVerification in HumanoidDescription APIs to enhance the security of loading character assets:

Thanks for your report!

2 Likes

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.