Security fixes land on the latest release of @cyanheads/git-mcp-server. Older
versions are not patched — upgrade to the current release.
Please do not open a public issue for security reports. Instead:
- Report privately via GitHub: Security tab → Report a vulnerability, or
- Email security@caseyjhand.com
Include a minimal reproduction where possible, with any API keys, tokens, or credentials redacted — a placeholder is enough to show the shape. You'll receive an acknowledgment, and credit in the release notes if the report leads to a fix (unless you prefer otherwise).