Only the latest released version of @apify/actors-mcp-server receives security updates.
Do not report security vulnerabilities through public GitHub issues.
Report vulnerabilities privately through one of these channels:
Follow Apify's vulnerability disclosure policy when testing or reporting a vulnerability.
Include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce it and a proof of concept, if available.
- The affected package version, endpoint, or commit.
- Your assessment of its severity and any suggested mitigation.
We will acknowledge your report within 5 business days and keep you informed while we investigate. Do not disclose the vulnerability publicly until it has been resolved or Apify has approved disclosure in writing.
This policy covers the source code in this repository and the @apify/actors-mcp-server package.
Report vulnerabilities affecting the hosted mcp.apify.com service or other Apify services through
Apify's vulnerability disclosure policy.
Community Actors and third-party services are outside this repository's scope. Report vulnerabilities in them to their respective maintainers.