Please don't open a public issue for security problems. Use GitHub's private vulnerability reporting instead ("Report a vulnerability" under the Security tab of this repository), and include:
- what an attacker can do and what they need (a normal game client, a rank, access to the console...)
- steps or a small script to reproduce it
- the MCScript version or commit and your Node.js version
You should get an answer within a week. Once a fix is released, you are credited in the changelog unless you would rather not be.
Only the latest release gets security fixes. MCScript 1.x is no longer maintained.
- Keep
verifyNameson for any server reachable from the internet. Without it anyone can log in as any name, including your owners. - Keep Node.js up to date. MCScript supports the Node.js releases that are still maintained (22, 24 and newer).
/pinstallruns third-party code with the same rights as the server. Only install plugins you trust.- The web panel listens on
127.0.0.1by default. If you expose it, put it behind HTTPS (a reverse proxy such as Caddy or nginx) and keep the token secret. The token gives full console access. - Only turn on
trustProxywhen the server sits behind your own reverse proxy. Otherwise players can fake their IP address and get around IP bans. - Don't run the server as root or Administrator.