Computer NetworksNETWORKS

Counter-Strike 2 XSS Exploit IP Capturer POC

Recently there has been a discovery that allows one to embed a HTML image tag into the vote kick window of panorama in Counter-Strike 2.
A PHP script posing as an image can be used to steal the IP addresses of the players connected that load up that image on their game client.


ip address


Alice AUSTIN is studying Cisco Systems Engineering. He has passion with both hardware and software and writes articles and reviews for many IT websites.

22 thoughts on “Counter-Strike 2 XSS Exploit IP Capturer POC

  • dead that bro took 5 attempts to write "callvote" LMAOOO

  • So this onky works if the attacker is in your team and starts a vote kick? So when you play five man with the boys, you are just fine?

  • Valve shits on its players. Neither the servers closed nor their players informed about it. Absolutely unworthy behavior for such a large company. Game and Steam permanently deleted.

  • so what? its just ip .. they cant do shit

  • Based gentleman playing the Ratchet and Clank 3 multiplayer lobby music.

  • Ayo, I have been playing CS2 for the past few days until I know about this now. I did witness some spam kicks in casual game and voted. So I am fucked basically right?

  • That explains why yesterday in my casual matches vote kick kept coming up a lot. I thought it was strange.

  • After cs2 release. I tested community servers too who is exterrnal. I searched for cs2 server and my Kaspersky Plus says Trojan reported from ip….face-orange-biting-nails I was just looking for community servers, not joining. WTF. And valve gameservers is open door too wtf xD and i found only bot servers full servers what ever seems like all honeypots !

  • Does this work when you use the sanitized names option?

Comments are closed.