You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
3. Include the following information in your report:
18
+
- Type of issue
19
+
- Full paths of source file(s) related to the issue
20
+
- Location of the affected source code
21
+
- Any special configuration required to reproduce the issue
22
+
- Step-by-step instructions to reproduce the issue
23
+
- Proof-of-concept or exploit code (if possible)
24
+
- Impact of the issue, including how an attacker might exploit it
25
+
26
+
## Response Process
27
+
28
+
We are committed to the following response process:
29
+
30
+
- We will acknowledge receipt of your vulnerability report within 3 business days
31
+
- We will provide an initial assessment of the report within 10 business days
32
+
- We will keep you informed of our progress throughout the process
33
+
- We will notify you when the vulnerability has been fixed
34
+
35
+
## Security Best Practices
36
+
37
+
When using the MCP Protocol Validator in your own projects, we recommend the following security best practices:
38
+
39
+
1.**Keep your dependencies updated**: Regularly update the MCP Protocol Validator and its dependencies to benefit from security patches
40
+
2.**Use caution with file operations**: When using the file operation tools in the MCP servers, be aware of potential security implications in your specific environment
41
+
3.**Control network access**: When using the HTTP MCP server, ensure it's only accessible to trusted clients or over secure networks
42
+
43
+
## Responsible Disclosure
44
+
45
+
We follow responsible disclosure principles. After a fix has been developed and released, we encourage security researchers to disclose the vulnerability in a responsible manner, giving users time to update their installations. We will credit security researchers who report valid vulnerabilities and work with us through the entire process.
46
+
47
+
48
+
Thank you for helping to keep the MCP Protocol Validator and its users secure!
0 commit comments