Skip to content

Security: WindowsGSH/WindowsGSH.Valheim

Security

SECURITY.md

Security policy

Security and trust

The Valheim module executes C# and starts the Valheim dedicated server with the current user's Windows permissions. WindowsGSH cannot guarantee arbitrary third-party or modified modules. Review source, manifests, dependencies, and download origins before use.

Download modules safely

Obtain the module from the official repository or another trusted source and install server files/mods through legitimate Steam/vendor sources. Review BepInEx and mods independently before use.

Protect credentials and server data

Protect server passwords, world data, crossplay identifiers, player data, logs, mods, configs, and backups. The vendor command line can expose the password to local process inspection, so redact diagnostics and restrict host access.

Report a vulnerability

Use the private repository advisory page. Do not publish exploits, credentials, private server data, or unredacted diagnostics.

Include in a report

Include module/WindowsGSH/server versions, crossplay mode, mod provenance, reproduction steps, impact, and sanitized diagnostics.

Supported versions

Security fixes target the latest module release and current WindowsGSH module API unless stated otherwise.

There aren't any published security advisories