Please do not report security vulnerabilities in public GitHub issues.
Send security reports to:
Include, when possible:
- affected MCNexus version;
- operating system and version;
- steps to reproduce;
- expected and observed behavior;
- logs, screenshots, or proof of concept details that do not expose private data;
- whether the issue affects licensing, installation, update delivery, local file permissions, or backend communication.
Do not include full license keys, personal data, production credentials, private certificates, or secrets in reports.
The project owner will review reports and may request additional information. Responsible disclosure is appreciated.