[BUG] Second critical vulnerability in MCP gateway — request for private security disclosure
Hi maintainers,
Following up on issue #4925, I have identified a second critical severity vulnerability in the MCP gateway component of the master (v6 development) branch.
As the private security advisory channel is unavailable and the security contact email appears undeliverable, I'm opening this issue to request a private communication channel (email / Discord DM) to share the full vulnerability report, root cause analysis, proof of concept and remediation recommendations.
I strictly follow responsible coordinated disclosure. I will not publish any technical details, exploit steps or code snippets publicly before a patched release is available. I can send both vulnerability reports together once a private channel is established.
Thanks, Qc
Source: micro/go-micro