| Version | Supported |
|---|---|
| 0.9.x | Yes |
| < 0.9.0 | No. Upgrade. Write tools in 0.8.0 and earlier send Partner API mutations with no confirmation gate. |
Use GitHub private vulnerability reporting for this repository:
- Open the Security tab on TMHSDigital/steam-mcp.
- Choose Report a vulnerability and file a private advisory.
If private reporting is not yet enabled, open a draft advisory from the Security Advisories page:
https://github.com/TMHSDigital/steam-mcp/security/advisories/new
Do not file a public issue, discussion, or pull request that includes exploit details for an undisclosed vulnerability.
We aim to acknowledge reports within 5 business days. We will keep the reporter updated as we reproduce, patch, and publish.
This project follows coordinated disclosure. We typically request about 90 days to ship a patch and release notes before a public writeup. We will not share reporter contact details or unpublished technical detail outside of people who need them to fix the issue.
Reported by Syed Anas Mohiuddin, Independent Researcher, Maintainer of mcp-safeguard
Disclosed as part of an MCP-server security research effort.