Back to Home
SECURITY PROGRAM

Security Disclosures

We take security seriously. If you discover a vulnerability in Raze, we want to hear about it. Responsible disclosure helps us protect everyone.

Disclosure Process

STEP 01

Discover

Find a potential vulnerability in Raze's systems, bot, dashboard, or API.

STEP 02

Report

Submit a detailed report via Discord DM to the development team with proof of concept.

STEP 03

Validate

Our team reviews the report, validates the issue, and assesses severity and impact.

STEP 04

Resolve

We patch the vulnerability and coordinate disclosure timing with the reporter.

In Scope

  • Raze Discord Bot (all shards and clusters)
  • Raze Web Dashboard (dashboard.raze-bot.dev)
  • Raze REST API (api.raze-bot.dev)
  • Raze WebSocket Gateway
  • OAuth2 authentication flows
  • Lavalink music node connections managed by Raze

Out of Scope

  • Discord's own infrastructure or API (report to Discord directly)
  • Third-party services not operated by Raze (hosting providers, Lavalink third-party nodes)
  • Social engineering attacks against Raze team members
  • Denial-of-service (DoS) attacks against our services
  • Issues already reported or known
  • Issues requiring physical access to our infrastructure

Severity Classification

CRITICALPriority recognition + Discord role
Remote code execution
Authentication bypass
Mass data exfiltration
Full server takeover via bot
HIGHDiscord role + public acknowledgment
Privilege escalation
Stored XSS on dashboard
API key/token leakage
Bypassing anti-nuke protections
MEDIUMPublic acknowledgment
CSRF on sensitive endpoints
Information disclosure
Broken access controls
Rate limit bypasses
LOWAcknowledgment in changelog
Minor information leaks
Non-sensitive data exposure
Low-impact logic flaws
UI-based issues

Report Guidelines

When submitting a report, please include:

  • 1Detailed description of the vulnerability
  • 2Steps to reproduce (step-by-step)
  • 3Proof of concept (screenshots, code, or request/response logs)
  • 4Affected component (bot command, dashboard endpoint, API route)
  • 5Potential impact assessment
  • 6Your Discord username for follow-up

Ready to Report?

Send your disclosure report via Discord DM to the development team. We acknowledge all reports within 48 hours.