Not a security issue? Bugs and feature requests go through the
issue forms; general questions are
covered by SUPPORT.md.
Only the most recent release is supported. Please update before reporting.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Anything older | No |
Please do not open a public issue for a security vulnerability.
Report it privately through GitHub:
- Go to the Security tab of this repository.
- Choose Report a vulnerability.
- Describe the issue, the version you tested, and how to reproduce it.
This is the only supported reporting channel. It keeps the report private until a fix ships and requires no contact details beyond your GitHub account.
- Acknowledgement: within 7 days.
- Assessment: within 30 days, with a decision on whether and when a fix will ship.
- Credit: if you want it, you will be credited in the release notes under whatever name or handle you choose. Say so in the report.
In scope: this application and the code in this repository.
Out of scope:
- Vulnerabilities in VRChat itself — report those to VRChat.
- Vulnerabilities inherited unmodified from upstream VRCX — report those upstream, and optionally tell us here so the fix can be tracked.
- Third-party dependencies — report upstream, then tell us.
Nyxall's VRCX is an independently maintained derivative of VRCX and is not affiliated with or endorsed by the upstream project. A report about this application should come here, not to them.
- Test against other people's accounts or data.
- Perform denial-of-service testing.
- Access, modify, or exfiltrate data that is not yours.
Redact before you attach anything. Logs, screenshots, and database excerpts routinely contain account emails, user IDs, and display names — yours and other people's. Remove them, or describe them rather than pasting them.