#203·mcp

Security: requesting private vulnerability reporting be enabled

Author: router0mailCreated Sep 13, 2026Updated Sep 13, 2026

Hi,

I found a security issue in the local WebSocket control channel (the server that bridges the MCP tool calls to the browser extension) — an unauthenticated-connection issue that lets untrusted code hijack the control channel.

This repo doesn't have GitHub's "Private vulnerability reporting" enabled and I couldn't find a SECURITY.md or security contact, so I don't want to post full technical details (root cause, exact file:line, and a working PoC) in a public issue before a fix is available.

Could you either:

  • enable Private vulnerability reporting (Settings → Code security → Report a vulnerability), or
  • share a security contact email

so I can send the full write-up privately? Happy to also just describe it here if you'd prefer to handle it in the open — your call.

Thanks!