All news
UpdatesJuly 8, 2026

MLSAC b45: safer punishments

/mlsac punish no longer hits innocent players, punishments need evidence, forged responses are rejected.

Flag 13 on our test server: “Suppression (Flag 13, stage 1/1): cmd ban” and a ban with an animation.

AFK players getting kicked

Root cause found: /mlsac punish matched players by partial name, so if the cheater had logged off, the punishment landed on a random player with a similar name. The name must now match exactly.

Evidence check

If a player has no VL, no buffer and no detections, /mlsac punish refuses to run. For special cases there is /mlsac punish <name> confirm. Every call and every refusal is logged with the issuer's name.

Forged response protection

Model responses are validated: any probability outside 0–1 (NaN, Infinity and other garbage) is rejected. A forged response can no longer inflate the buffer into an instant kick.

Names with special characters

Names with spaces and special characters (Bedrock/Geyser) are no longer substituted into console commands — such a name could previously redirect a punishment to another player. These offenders are kicked directly through the API instead. In the Suspects menu, [console] and [player] actions are blocked for unsafe names.

File writes

CSV writes outside the plugin folder through a crafted name are closed off.

Punishment cooldown

The cooldown now also applies to raw commands (kick, ban, mute without a prefix) — no more kick storms on a burst of flags. These punishments are reported to the API too, so the dashboard history is fuller.

Minor

Cross-server alerts are sanitised, server-driven sequence updates are limited to a safe range, and the console warns if the backend is connected over http:// instead of https://.