| Version | Supported |
|---|---|
| 0.2.x | Yes |
| < 0.2 | No |
If you discover a security vulnerability in osint-mcp-server, please report it responsibly.
Do NOT open a public issue.
Instead, email contact@orhanyildirim.us with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive a response within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.
This policy covers the osint-mcp-server codebase only — not the third-party APIs it connects to (Shodan, VirusTotal, Censys, etc.).