Please do not publish credentials, exploit details, personal data, or an unpatched vulnerability in a public issue.
Use GitHub's private vulnerability reporting or Security Advisory flow for the Flametrap repository. Include:
- the affected Flametrap version or commit;
- the smallest reproducible example;
- the expected and actual behavior;
- whether Roblox, Discord, Cloudflare, or the local filesystem is involved.
Flametrap must not:
- request or store Roblox passwords, two-factor codes, backup codes, or
.ROBLOSECURITYcookies; - inject DLLs or scripts into Roblox;
- read or write Roblox process memory;
- disable antivirus, anti-cheat, or the Roblox updater;
- execute code from imported cursor, sound, texture, or FastFlag packages;
- include Cloudflare tokens, D1 credentials, signing certificates, or local
.wranglerstate in releases.
Imported ZIPs and FlagHub packages must remain data-only, size-bounded, and path-traversal safe. Local replacements should be backed up before writes and restorable without reinstalling Roblox.
Security fixes target the latest published Flametrap version. Older builds may stop working when Roblox changes its client, APIs, or supported settings.