Hi — as part of independent security research on MCP servers, I believe I found a security-relevant issue affecting Windows deployments of one of this repo's tools.
I don't see a SECURITY.md or GitHub private vulnerability reporting enabled on this repository, so I don't have a private channel to share technical details safely.
Could you enable GitHub's private vulnerability reporting (Settings → Code security and analysis → Private vulnerability reporting) or share an alternate private contact? I'd rather not post specifics in a public issue.
Happy to follow a 90-day coordinated disclosure timeline from acknowledgment.
— Matías Zabal Jáuregui (zabaljauregui@gmail.com)
Hi — as part of independent security research on MCP servers, I believe I found a security-relevant issue affecting Windows deployments of one of this repo's tools.
I don't see a SECURITY.md or GitHub private vulnerability reporting enabled on this repository, so I don't have a private channel to share technical details safely.
Could you enable GitHub's private vulnerability reporting (Settings → Code security and analysis → Private vulnerability reporting) or share an alternate private contact? I'd rather not post specifics in a public issue.
Happy to follow a 90-day coordinated disclosure timeline from acknowledgment.
— Matías Zabal Jáuregui (zabaljauregui@gmail.com)