Security fixes are provided for the latest published release.
| Version | Supported |
|---|---|
| 1.x | Yes |
| Earlier or unreleased forks | No |
Do not open a public issue for a suspected vulnerability or include exploit details, credentials, personal data, or customer information in a public report.
Use GitHub's private vulnerability reporting feature for this repository:
- Open the repository's Security tab.
- Choose Report a vulnerability.
- Include the affected version, impact, reproducible steps, and the minimum proof needed to confirm the issue.
If private vulnerability reporting is temporarily unavailable, use Vucar's contact page to request a private security channel. Do not include exploit details, credentials, or personal data in that initial request.
Maintainers will acknowledge a complete report as soon as reasonably possible, investigate it, and coordinate remediation and disclosure. Please allow time for a fix before publishing details.
In scope:
- Marketplace and plugin manifest behavior.
- Unexpected tools, privileges, or data returned by the Vucar public MCP endpoint.
- Authentication or authorization bypasses.
- Injection, request-smuggling, cross-origin, denial-of-service, or sensitive-data exposure affecting the endpoint.
Out of scope:
- High-volume automated testing or traffic that affects service availability.
- Social engineering, physical attacks, or testing third-party AI clients.
- Vehicle-estimate accuracy disagreements that do not involve a security flaw.
Never test with real personal information. Use synthetic vehicle data only.