Skip to content

Security: DocHubInc/dochub-mcp-server

SECURITY.md

Security Policy

Reporting a vulnerability

If you believe you have found a security vulnerability in the DocHub MCP server or the DocHub platform, please report it privately — do not open a public GitHub issue.

Preferred: use GitHub private vulnerability reporting — Report a vulnerability. Your report is visible only to the maintainers, and we can collaborate on a fix privately.

Alternatively: email security@dochub.com.

Please include:

  • A description of the issue and its impact
  • Steps to reproduce
  • Any relevant request/response traces (with tokens redacted)

We will acknowledge your report and keep you informed of the fix status.

Scope

This repository contains documentation and client configuration only; the MCP server itself runs as a hosted service at https://dochub.com/mcp. Vulnerability reports for the hosted service, its OAuth flows, and the DocHub API are all welcome through the contact above.

There aren't any published security advisories