Security Bulletins

This section contains notifications about security vulnerabilities in Engine and Engine Dispatch. Click "Follow" to receive notifications.

  • Cross-Site Scripting Vulnerability

    Announced: 2022-05-27 Vulnerability In Rustici Engine version 2017.1 and above, the player (both modern and legacy) is a static page that is given a url to use in retrieving the information it needs to launc...

  • Signed Launch Link Security Vulnerability

    Announced: 2020-06-25   Vulnerability A flaw exists in the API v2 OAuth access token scope evaluation.  Tokens generated in API responses for signed launch links can be used as highly privileged API access t...