The following versions of this project are currently supported with security updates:
| Version | Supported |
|---|---|
| 0.1.x | ✅ Yes |
| < 0.1.0 | ❌ No |
We take the security of OpenMCP seriously. If you believe you have found a security vulnerability in this repository or its related services (including MCP server connections, plugin protocols, or OpenMCP SDK), we encourage you to report it responsibly.
To report a vulnerability:
- Please send an email to zhelonghuang@qq.com
- Include a detailed description of the issue, steps to reproduce, and (if possible) a minimal proof-of-concept (PoC).
- Please do not disclose security issues publicly until we have had a chance to investigate and issue a patch.
We aim to respond to all security reports within 7 business days and will work with you to verify and resolve the issue promptly.
We follow a coordinated disclosure process:
- We appreciate private disclosure first.
- We may publish advisories or patch notes when the issue is fixed.
- You’re welcome to coordinate timing for public blog posts or CVE publication with us.
Currently, we do not operate a formal bug bounty program. However, high-impact or novel vulnerabilities may receive recognition in release notes, project acknowledgments, or future community-based bounty collaborations.
- Email: zhelonghuang@qq.com
- Discord: Join our Discord
- WeChat: contact
lstmkirigaya - QQ Group: 782833642
We appreciate your effort to make OpenMCP better and safer 💙