If you discover a security vulnerability in mcp-use, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
- GitHub Security Advisories: Use GitHub's private vulnerability reporting
- Email: security@manufact.com
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Assessment: Within 1 week
- Fix: Depends on severity
For anything related to Manufact Cloud please report any findings at security@manufact.com
- Review server permissions before connecting to any MCP server
- Use environment variables for secrets — never hardcode them
- Limit server access to only required tools and resources
- Keep dependencies updated to patch known vulnerabilities