The P4MCP Server interacts with Perforce servers and may handle credentials and workspace configurations.
Security is important to us. If you discover a security vulnerability, please report it responsibly.
Please do not open a public issue for security vulnerabilities.
Instead:
- Use GitHub Security Advisories (if enabled), or
- Contact the maintainers privately via the repository maintainers, or
- Report via our dedicated support email for vulnerabilities
Include the following information:
- A description of the vulnerability
- Steps to reproduce (if applicable)
- Its potential impact
- Suggested mitigation (if known)
Please remove any sensitive credentials before sharing logs.
Examples include:
- Credential exposure or leakage
- Unsafe default behavior that allows unintended destructive operations
- Improper permission handling
- Injection vulnerabilities in command execution
- Privilege escalation scenarios
If you are unsure whether something qualifies as a security issue, report it privately.
Thank you for helping keep P4MCP Server secure.