Executor HTTP request vulnerability fix
Key RequiredUniversal

Executor HTTP request vulnerability fix

Universal ScriptDanny_Danny_ 1.4K views 236 executesUpdated Jan 21, 2026
2.5/ 5(4 votes)
2250% Positive
Lua Script•61 lines (1719 chars)
local function getUrl(url)
	url = url.Url or url
	return type(url) == "string" and url or nil
end

local function verifyUrl(url)
	local lower = url:lower()
	return lower:sub(1, 7) == "http://" or lower:sub(1, 8) == "https://"
end

local function wrap(func, method)
	if type(func) ~= "function" then return end
	return function(...)
		local packed = { ... }
		local url = method and getUrl(packed[2]) or getUrl(packed[1])
		if url then
			if verifyUrl(url) then
				local success, result = pcall(function() return func(table.unpack(packed)) end)
				if success then
					return result
				else
					error(result, method and 3 or 2)
				end
			else
				error("URL must be http", method and 3 or 2)
			end
		else
			error("invalid url", method and 3 or 2)
		end
	end
end


local env = getgenv()
if type(env.request) == "function" then env.request = wrap(env.request) end
if type(env.http_request) == "function" then env.http_request = wrap(env.http_request) end
if type(env.http) == "table" and type(env.http.request) == "function" then
	env.http.request = wrap(env.http.request)
end
if type(env.HttpGet) == "function" then env.HttpGet = wrap(env.HttpGet) end
if type(env.HttpGetAsync) == "function" then env.HttpGetAsync = wrap(env.HttpGetAsync) end


local wrappedHttpGet = wrap(game.HttpGet, true)
local wrappedHttpGetAsync = wrap(game.HttpGetAsync, true)

local mt = getrawmetatable(game)
local oldnc = mt.__namecall
setreadonly(mt, false)
mt.__namecall = function(...)
	local method = getnamecallmethod()
	if checkcaller() then
		if method == "HttpGet" then
			return wrappedHttpGet(...)
		elseif method == "HttpGetAsync" then
			return wrappedHttpGetAsync(...)
		end
	end
	return oldnc(...)
end
setreadonly(mt, true)

Features & Information

This script is for people who use executors such as Seliware with the vulnerability that allows scripts to access your local file system. I'd still be careful running random scripts but this should at least give some amount of protection. I recommend leaving this in your autoexecute. If you have any suggestions on how I can improve this script, PLEASE comment them. I'll be more than happy to see what I can do about it. You can also use the loadstring to always receive the latest version of this script loadstring(game:HttpGet("https://scriptblox.com/api/script/raw/Universal-Script-Executor-HTTP-request-vulnerability-fix-88720"))()

Community Comments (2)

methawmethawJan 21, 2026

this is amazing, but they still not fixed the vuln lol

pypipypiMar 2, 2026

@qluelez pal pls just publish a new script and call it "Executor HTTP request vulnerability fix V2"

More Scripts for Universal Scripts