Please do not disclose suspected vulnerabilities in a public issue.
Email support@gummble.com with the subject
[Security] Gummble MCP vulnerability. Include:
- the affected endpoint, client, or OAuth flow;
- clear reproduction steps;
- the potential impact;
- relevant logs or screenshots with credentials and personal data removed;
- a safe way to contact you for follow-up.
We aim to acknowledge complete reports within three business days and will share status updates while we investigate. Please allow reasonable time for a fix before publishing details.
Reports may cover:
https://mcp.gummble.com/mcp;- Gummble MCP OAuth and authorization behavior;
- unintended access to private account or product data;
- credential, token, or session exposure;
- security-sensitive errors in the registry metadata or setup documentation.
Billing questions, feature requests, availability incidents, and documentation corrections belong in SUPPORT.md or the public issue tracker.
Gummble MCP is a managed service. Security fixes apply to the current hosted version; users do not need to update a package from this repository.