Skip to content

Security: LSTM-Kirigaya/openmcp-client

SECURITY.md

Security Policy

Supported Versions

The following versions of this project are currently supported with security updates:

Version Supported
0.1.x ✅ Yes
< 0.1.0 ❌ No

Reporting a Vulnerability

We take the security of OpenMCP seriously. If you believe you have found a security vulnerability in this repository or its related services (including MCP server connections, plugin protocols, or OpenMCP SDK), we encourage you to report it responsibly.

To report a vulnerability:

  • Please send an email to zhelonghuang@qq.com
  • Include a detailed description of the issue, steps to reproduce, and (if possible) a minimal proof-of-concept (PoC).
  • Please do not disclose security issues publicly until we have had a chance to investigate and issue a patch.

We aim to respond to all security reports within 7 business days and will work with you to verify and resolve the issue promptly.

Disclosure Policy

We follow a coordinated disclosure process:

  • We appreciate private disclosure first.
  • We may publish advisories or patch notes when the issue is fixed.
  • You’re welcome to coordinate timing for public blog posts or CVE publication with us.

Bug Bounty

Currently, we do not operate a formal bug bounty program. However, high-impact or novel vulnerabilities may receive recognition in release notes, project acknowledgments, or future community-based bounty collaborations.

Contact

We appreciate your effort to make OpenMCP better and safer 💙

Learn more about advisories related to LSTM-Kirigaya/openmcp-client in the GitHub Advisory Database