Skip to content

Security: MRLuke956/ModMenuCrew

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
6.0.8 ✅ Active
< 6.0.8 ❌ End of life

Reporting a Vulnerability

If you discover a security vulnerability in ModMenuCrew, please report it responsibly.

How to Report

  1. Do NOT open a public issue for security vulnerabilities
  2. Contact us privately via one of these channels:

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 1 week
  • Fix: Depends on severity, typically within 2 weeks for critical issues

Scope

This policy covers:

  • The ModMenuCrew BepInEx plugin source code
  • The custom RPC messaging system
  • Any authentication or license validation logic

This policy does not cover:

  • Among Us game vulnerabilities (report to Innersloth)
  • BepInEx framework vulnerabilities (report to BepInEx maintainers)

Responsible Disclosure

We appreciate responsible disclosure and will credit security researchers (with permission) in our release notes.

There aren’t any published security advisories