Skip to content

Item duplication: AddParachute and resetArmor grant items with no checks #504

Description

@Pajt9whauht283as

Description

Two events in server/consumables.lua (lines 120-130) grant items to any player with no ownership, cooldown, or source check:

RegisterNetEvent('consumables:server:AddParachute', function()
    local Player = exports['qb-core']:GetPlayer(source)
    if not Player then return end
    exports['qb-inventory']:AddItem(source, 'parachute', 1, false, false, 'consumables:server:AddParachute')
end)

RegisterNetEvent('consumables:server:resetArmor', function()
    local Player = exports['qb-core']:GetPlayer(source)
    if not Player then return end
    exports['qb-inventory']:AddItem(source, 'heavyarmor', 1, false, false, 'consumables:server:resetArmor')
end)

Both handlers only verify the player object exists. The client is supposed to fire these as part of specific flows (parachute deployment from an aircraft / armor reset after respawn), but since there is no server-side condition whatsoever, any client can trigger them in a loop:

  • consumables:server:AddParachute -> infinite parachute items
  • consumables:server:resetArmor -> infinite heavyarmor items

heavyarmor is a valuable item: consumables:server:useHeavyArmor (lines 132-139) consumes one and sets the player to 100 armor - so a player can have unlimited max armor forever, or flood the market with heavyarmor to sell.

Impact

  • Unlimited item duplication (parachute, heavyarmor)
  • Permanent max armor via unlimited heavyarmor
  • Market flooding / economy impact if heavyarmor is sellable on the server

Suggested fix

  • Gate the events behind real server-side state: e.g. track that the player is actually in a vehicle/plane (for parachute) and that they just respawned (for armor), or remove these events entirely and grant the items from the server-side flow that legitimately triggers them (death/respawn handler).
  • Add a cooldown and server-side validation of the trigger source.

Affected file

server/consumables.lua - consumables:server:AddParachute, consumables:server:resetArmor

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions