Developer postOriginal post (opens in a new tab)

[IMPORTANT] SDK2013 engine file upload and execution exploit

Hello everyone,

It has come to our attention that a new exploit for Source SDK Base 2013 (the engine PVKII is running on) has been discovered. (more info)

We heard that the exploit seems to use a glitch with sprays/custom sounds. The vulnerability allows the attacker to run malicious files on your computer.

Use this workaround to make sure you are safe from the exploit:

  • Open console
  • cl_allowdownload 0
  • cl_allowupload 0
  • cl_customsounds 0
  • Disable sprays (cl_playerspraydisable 1)
  • Disable downloading of custom files (cl_downloadfilter none)

We will keep this post updated with new information as we receive it.