Skip to content

Request: enable Private Vulnerability Reporting (or share a security contact) #7

Description

@GeeksikhSecurity

Hi — thanks for mcpx.

I'd like to report a security issue privately in the published @teampitch/mcpx package. I can't find a
private channel: Private Vulnerability Reporting isn't enabled and there's no SECURITY.md / security contact.

Could you either enable Private Vulnerability Reporting (Settings → Security → "Private vulnerability
reporting" → Enable
) or reply here / by email with a private contact I can send details to?
I'm deliberately keeping all specifics out of this public thread. (If this GitHub repo isn't where @teampitch/mcpx is maintained,
a pointer to the right place would help.)

For a clear, good-faith timeline: if I don't hear back by 18 September 2026 (30 days), I'll proceed under
standard coordinated disclosure — reporting through a third-party coordinator (e.g. huntr) and/or the GitHub
Advisory Database so the issue can be triaged and a fix coordinated, with public disclosure no earlier than
17 November 2026 (90 days). I'd much rather coordinate with you directly first. Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions