FrostWeb Studios takes the security of our software seriously. We appreciate responsible disclosure of vulnerabilities affecting any of our repositories, services, games, or plugins.
Please do not file public issues for security vulnerabilities.
Report privately via one of the following channels:
- Email: security@frostweb.studio
- GitHub Security Advisories: open a draft advisory on the affected repository
When reporting, please include:
- A description of the vulnerability and its impact
- Steps to reproduce, or a proof-of-concept
- The affected service, plugin, version, or commit SHA
- Your name and contact info (if you'd like credit)
- Acknowledgement within 72 hours
- An initial assessment and severity rating within 7 days
- A fix or mitigation plan within 30 days for High/Critical findings
- Credit in the release notes (if desired) once a patch is available
In scope:
- All repositories under the
FrostWeb-StudiosGitHub organization - Production services at
*.frostweb.studioand*.frostweb.dev - Live games and their dedicated-server / client builds
- FW UE5 plugins (FWGASSystem, FWOnlineAuth, FWChatSystem, etc.)
Out of scope:
- Third-party services we integrate with (Steam, Stripe, PayPal, Discord)
- Social-engineering or physical attacks
- Denial-of-service testing against production
- Vulnerabilities requiring physical access to a user's device
We will not pursue legal action against researchers who:
- Act in good faith and follow this policy
- Avoid privacy violations, data destruction, and service disruption
- Give us reasonable time to remediate before disclosure
Thank you for helping keep FrostWeb players and contributors safe.