Description
Two events in server/consumables.lua (lines 120-130) grant items to any player with no ownership, cooldown, or source check:
RegisterNetEvent('consumables:server:AddParachute', function()
local Player = exports['qb-core']:GetPlayer(source)
if not Player then return end
exports['qb-inventory']:AddItem(source, 'parachute', 1, false, false, 'consumables:server:AddParachute')
end)
RegisterNetEvent('consumables:server:resetArmor', function()
local Player = exports['qb-core']:GetPlayer(source)
if not Player then return end
exports['qb-inventory']:AddItem(source, 'heavyarmor', 1, false, false, 'consumables:server:resetArmor')
end)
Both handlers only verify the player object exists. The client is supposed to fire these as part of specific flows (parachute deployment from an aircraft / armor reset after respawn), but since there is no server-side condition whatsoever, any client can trigger them in a loop:
consumables:server:AddParachute -> infinite parachute items
consumables:server:resetArmor -> infinite heavyarmor items
heavyarmor is a valuable item: consumables:server:useHeavyArmor (lines 132-139) consumes one and sets the player to 100 armor - so a player can have unlimited max armor forever, or flood the market with heavyarmor to sell.
Impact
- Unlimited item duplication (parachute, heavyarmor)
- Permanent max armor via unlimited heavyarmor
- Market flooding / economy impact if heavyarmor is sellable on the server
Suggested fix
- Gate the events behind real server-side state: e.g. track that the player is actually in a vehicle/plane (for parachute) and that they just respawned (for armor), or remove these events entirely and grant the items from the server-side flow that legitimately triggers them (death/respawn handler).
- Add a cooldown and server-side validation of the trigger source.
Affected file
server/consumables.lua - consumables:server:AddParachute, consumables:server:resetArmor
Description
Two events in
server/consumables.lua(lines 120-130) grant items to any player with no ownership, cooldown, or source check:Both handlers only verify the player object exists. The client is supposed to fire these as part of specific flows (parachute deployment from an aircraft / armor reset after respawn), but since there is no server-side condition whatsoever, any client can trigger them in a loop:
consumables:server:AddParachute-> infiniteparachuteitemsconsumables:server:resetArmor-> infiniteheavyarmoritemsheavyarmoris a valuable item:consumables:server:useHeavyArmor(lines 132-139) consumes one and sets the player to 100 armor - so a player can have unlimited max armor forever, or flood the market with heavyarmor to sell.Impact
Suggested fix
Affected file
server/consumables.lua-consumables:server:AddParachute,consumables:server:resetArmor