Skip to content

Security: gummble/gummble-mcp-server

SECURITY.md

Security policy

Reporting a vulnerability

Please do not disclose suspected vulnerabilities in a public issue.

Email support@gummble.com with the subject [Security] Gummble MCP vulnerability. Include:

  • the affected endpoint, client, or OAuth flow;
  • clear reproduction steps;
  • the potential impact;
  • relevant logs or screenshots with credentials and personal data removed;
  • a safe way to contact you for follow-up.

We aim to acknowledge complete reports within three business days and will share status updates while we investigate. Please allow reasonable time for a fix before publishing details.

Scope

Reports may cover:

  • https://mcp.gummble.com/mcp;
  • Gummble MCP OAuth and authorization behavior;
  • unintended access to private account or product data;
  • credential, token, or session exposure;
  • security-sensitive errors in the registry metadata or setup documentation.

Billing questions, feature requests, availability incidents, and documentation corrections belong in SUPPORT.md or the public issue tracker.

Supported version

Gummble MCP is a managed service. Security fixes apply to the current hosted version; users do not need to update a package from this repository.

There aren't any published security advisories