Skip to content

Security: sdemonzdevelopment-spec/RedstoneReboot

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.4.x ✅ Active support
1.3.x ✅ Active support
< 1.3 ❌ No longer supported

Reporting a Vulnerability

If you discover a security vulnerability in RedstoneReboot, please do not open a public issue.

To report a security vulnerability, please use GitHub's Private Vulnerability Reporting feature at https://github.com/sdemonzdevelopment-spec/RedstoneReboot/security/advisories/new

Alternatively, you may report it privately through one of the following channels:

We will acknowledge your report within 72 hours and aim to release a fix within 7 days for confirmed vulnerabilities.

Scope

Security reports are accepted for:

  • Authentication bypass in the Pterodactyl backend (API key exposure, token leaks)
  • Remote code execution through command injection
  • Unintended file system access through LocalScript backend or config parsing
  • Environment variable leakage through BackendConfig property resolution

Reports about denial-of-service through intentional misconfiguration or features working as designed are out of scope.

There aren't any published security advisories