Security: requesting private vulnerability reporting be enabled
Author: router0mailCreated Sep 13, 2026Updated Sep 13, 2026
Hi,
I found a security issue in the local WebSocket control channel (the server that bridges the MCP tool calls to the browser extension) — an unauthenticated-connection issue that lets untrusted code hijack the control channel.
This repo doesn't have GitHub's "Private vulnerability reporting" enabled and I couldn't find a SECURITY.md or security contact, so I don't want to post full technical details (root cause, exact file:line, and a working PoC) in a public issue before a fix is available.
Could you either:
- enable Private vulnerability reporting (Settings → Code security → Report a vulnerability), or
- share a security contact email
so I can send the full write-up privately? Happy to also just describe it here if you'd prefer to handle it in the open — your call.
Thanks!
Source: BrowserMCP/mcp