If you believe you have found a security vulnerability in the DocHub MCP server or the DocHub platform, please report it privately — do not open a public GitHub issue.
Preferred: use GitHub private vulnerability reporting — Report a vulnerability. Your report is visible only to the maintainers, and we can collaborate on a fix privately.
Alternatively: email security@dochub.com.
Please include:
- A description of the issue and its impact
- Steps to reproduce
- Any relevant request/response traces (with tokens redacted)
We will acknowledge your report and keep you informed of the fix status.
This repository contains documentation and client configuration only; the MCP server itself runs as a hosted service at https://dochub.com/mcp. Vulnerability reports for the hosted service, its OAuth flows, and the DocHub API are all welcome through the contact above.