Hi — thanks for mcpx.
I'd like to report a security issue privately in the published @teampitch/mcpx package. I can't find a
private channel: Private Vulnerability Reporting isn't enabled and there's no SECURITY.md / security contact.
Could you either enable Private Vulnerability Reporting (Settings → Security → "Private vulnerability
reporting" → Enable) or reply here / by email with a private contact I can send details to?
I'm deliberately keeping all specifics out of this public thread. (If this GitHub repo isn't where @teampitch/mcpx is maintained,
a pointer to the right place would help.)
For a clear, good-faith timeline: if I don't hear back by 18 September 2026 (30 days), I'll proceed under
standard coordinated disclosure — reporting through a third-party coordinator (e.g. huntr) and/or the GitHub
Advisory Database so the issue can be triaged and a fix coordinated, with public disclosure no earlier than
17 November 2026 (90 days). I'd much rather coordinate with you directly first. Thanks!
Hi — thanks for mcpx.
I'd like to report a security issue privately in the published
@teampitch/mcpxpackage. I can't find aprivate channel: Private Vulnerability Reporting isn't enabled and there's no
SECURITY.md/ security contact.Could you either enable Private Vulnerability Reporting (Settings → Security → "Private vulnerability
reporting" → Enable) or reply here / by email with a private contact I can send details to?
I'm deliberately keeping all specifics out of this public thread. (If this GitHub repo isn't where
@teampitch/mcpxis maintained,a pointer to the right place would help.)
For a clear, good-faith timeline: if I don't hear back by 18 September 2026 (30 days), I'll proceed under
standard coordinated disclosure — reporting through a third-party coordinator (e.g. huntr) and/or the GitHub
Advisory Database so the issue can be triaged and a fix coordinated, with public disclosure no earlier than
17 November 2026 (90 days). I'd much rather coordinate with you directly first. Thanks!