Security report (responsible disclosure - no public PoC details)
Private vulnerability reporting is not enabled on this repository and there is no SECURITY.md, so I am reporting here publicly per GitHub guidelines. Happy to share full details privately.
Summary
The qb-banking:server:withdraw callback accepts a negative amount with no server-side validation. A negative withdrawal CREDITS the attacker's shared bank account balance, and the balance can then be withdrawn as real cash - unlimited in-game money, no job/admin/existing balance required.
Affected code
server.lua:211 - CreateCallback('qb-banking:server:withdraw', ...)
server.lua:216 - local withdrawAmount = tonumber(data.amount) - no sign/type validation
server.lua:232 - if accountBalance < withdrawAmount then return ... - balance guard is bypassed by negative values (0 < -10000 is false, so the check passes)
server.lua:117-135 - internal RemoveMoney:
server.lua:127 - account_balance = account_balance - amount - subtracting a negative amount increases the balance
server.lua:131 - same negative math persisted via UPDATE bank_accounts SET account_balance = account_balance - ?
Impact
Repeat withdraw with negative amounts on your own shared account to grow its balance without limit, then withdraw positive to cash (server.lua:234 - Player.AddMoney('cash', withdrawAmount)). Any player can generate unlimited cash on any server using qb-banking.
Additional observation (same root cause)
Job/gang account authorization (server.lua:229-230) only checks job.name ~= accountName and not job.isboss - any regular member whose job name matches the account name can withdraw from the shared job account (e.g. any police officer can drain the police account). Combined with the negative amount bug, this also allows crediting job accounts.
Suggested fix
- Validate server-side in
withdraw/deposit/transfer callbacks: reject non-numeric and amount <= 0 values.
- Add the same guard inside internal
AddMoney/RemoveMoney (lines ~80-137) so the exported helpers cannot be misused by third-party resources either.
I can provide a full proof of concept privately. No exploit details have been published anywhere.
Security report (responsible disclosure - no public PoC details)
Private vulnerability reporting is not enabled on this repository and there is no SECURITY.md, so I am reporting here publicly per GitHub guidelines. Happy to share full details privately.
Summary
The
qb-banking:server:withdrawcallback accepts a negativeamountwith no server-side validation. A negative withdrawal CREDITS the attacker's shared bank account balance, and the balance can then be withdrawn as real cash - unlimited in-game money, no job/admin/existing balance required.Affected code
server.lua:211-CreateCallback('qb-banking:server:withdraw', ...)server.lua:216-local withdrawAmount = tonumber(data.amount)- no sign/type validationserver.lua:232-if accountBalance < withdrawAmount then return ...- balance guard is bypassed by negative values (0 < -10000is false, so the check passes)server.lua:117-135- internalRemoveMoney:server.lua:127-account_balance = account_balance - amount- subtracting a negative amount increases the balanceserver.lua:131- same negative math persisted viaUPDATE bank_accounts SET account_balance = account_balance - ?Impact
Repeat withdraw with negative amounts on your own shared account to grow its balance without limit, then withdraw positive to cash (
server.lua:234-Player.AddMoney('cash', withdrawAmount)). Any player can generate unlimited cash on any server using qb-banking.Additional observation (same root cause)
Job/gang account authorization (
server.lua:229-230) only checksjob.name ~= accountName and not job.isboss- any regular member whose job name matches the account name can withdraw from the shared job account (e.g. any police officer can drain thepoliceaccount). Combined with the negative amount bug, this also allows crediting job accounts.Suggested fix
withdraw/deposit/transfer callbacks: reject non-numeric andamount <= 0values.AddMoney/RemoveMoney(lines ~80-137) so the exported helpers cannot be misused by third-party resources either.I can provide a full proof of concept privately. No exploit details have been published anywhere.