Skip to content

Security: Chovei/Nyxalls-VRCX

.github/SECURITY.md

Security Policy

Not a security issue? Bugs and feature requests go through the issue forms; general questions are covered by SUPPORT.md.

Supported versions

Only the most recent release is supported. Please update before reporting.

Version Supported
Latest release Yes
Anything older No

Reporting a vulnerability

Please do not open a public issue for a security vulnerability.

Report it privately through GitHub:

  1. Go to the Security tab of this repository.
  2. Choose Report a vulnerability.
  3. Describe the issue, the version you tested, and how to reproduce it.

This is the only supported reporting channel. It keeps the report private until a fix ships and requires no contact details beyond your GitHub account.

What to expect

  • Acknowledgement: within 7 days.
  • Assessment: within 30 days, with a decision on whether and when a fix will ship.
  • Credit: if you want it, you will be credited in the release notes under whatever name or handle you choose. Say so in the report.

Scope

In scope: this application and the code in this repository.

Out of scope:

  • Vulnerabilities in VRChat itself — report those to VRChat.
  • Vulnerabilities inherited unmodified from upstream VRCX — report those upstream, and optionally tell us here so the fix can be tracked.
  • Third-party dependencies — report upstream, then tell us.

Nyxall's VRCX is an independently maintained derivative of VRCX and is not affiliated with or endorsed by the upstream project. A report about this application should come here, not to them.

Please do not

  • Test against other people's accounts or data.
  • Perform denial-of-service testing.
  • Access, modify, or exfiltrate data that is not yours.

When you write the report

Redact before you attach anything. Logs, screenshots, and database excerpts routinely contain account emails, user IDs, and display names — yours and other people's. Remove them, or describe them rather than pasting them.

There aren't any published security advisories