Skip to content

Security: kurocries/Flametrap

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not publish credentials, exploit details, personal data, or an unpatched vulnerability in a public issue.

Use GitHub's private vulnerability reporting or Security Advisory flow for the Flametrap repository. Include:

  • the affected Flametrap version or commit;
  • the smallest reproducible example;
  • the expected and actual behavior;
  • whether Roblox, Discord, Cloudflare, or the local filesystem is involved.

Project boundaries

Flametrap must not:

  • request or store Roblox passwords, two-factor codes, backup codes, or .ROBLOSECURITY cookies;
  • inject DLLs or scripts into Roblox;
  • read or write Roblox process memory;
  • disable antivirus, anti-cheat, or the Roblox updater;
  • execute code from imported cursor, sound, texture, or FastFlag packages;
  • include Cloudflare tokens, D1 credentials, signing certificates, or local .wrangler state in releases.

Imported ZIPs and FlagHub packages must remain data-only, size-bounded, and path-traversal safe. Local replacements should be backed up before writes and restorable without reinstalling Roblox.

Supported versions

Security fixes target the latest published Flametrap version. Older builds may stop working when Roblox changes its client, APIs, or supported settings.

There aren't any published security advisories