We currently support the following versions of the LeanMCP SDK:
| Version | Supported |
|---|---|
| 0.5.x | ✅ |
| 0.4.x | ✅ |
| < 0.4.0 | ❌ |
We take the security of LeanMCP very seriously. If you have found a security vulnerability in LeanMCP, we appreciate your help in disclosing it to us in a responsible manner.
Please do not report security vulnerabilities through public GitHub issues.
If you believe you have found a vulnerability, please email us immediately at:
Please include as much information as possible to help us reproduce and fix the issue, including:
- Steps to reproduce the vulnerability
- Version of LeanMCP being used
- Any relevant code snippets or configuration files
- Response: We will acknowledge your report within 48 hours.
- Investigation: We will investigate the issue and determine its impact.
- Fix: We will work on a fix and release a security patch as soon as possible.
- Disclosure: Once the fix is released, we will publicly disclose the vulnerability and credit you for your discovery (if you wish).
- Keep Dependencies Updated: regularly run
npm updateor useleanmcp-sdk/scripts/publish-sync.shto keep your SDK versions in sync. - Environment Variables: Never commit
.envfiles. Use the built-in environment variable injection securely. - Authentication: Always use
@leanmcp/authfor securing your MCP servers when exposing them over the internet.
Thank you for helping keep LeanMCP safe!