HomeFeaturesDocumentationContactDownload
Browse the docs

Security disclosure

How to report a security vulnerability in SiteCMD and what happens after you do.

Report suspected vulnerabilities privately so we can investigate and coordinate a fix before details become public.

How to report

For the desktop app, standalone CLI, bundled MCP server, or release infrastructure, use GitHub's private vulnerability reporting. The desktop repository's security policy defines supported versions, scope, and the encrypted contact option.

For sitecmd.com or a hosted SiteCMD service, email support@sitecmd.com with "security" in the subject. This is the public contact in security.txt. Contributors with access to the private web repository can also use its private vulnerability-reporting form.

Include the affected component and version or URL, a description of the impact, and enough evidence to investigate. Tell us whether you want public credit. Do not include other users' data or publish secrets in an issue or discussion.

Scope

Relevant reports include vulnerabilities in:

  • The desktop app, CLI, MCP server, and local data or credential handling
  • Release signing, updates, installation, and distribution
  • The website and hosted license, OAuth, catalog, telemetry, connected-site, and scanning services
  • Authorization, tenant isolation, consent, and data-retention boundaries

A scanner finding is not automatically a vulnerability, but it is not automatically out of scope either. Explain the concrete impact on SiteCMD or its users. Follow the applicable repository security policy when evaluating scope.

Research boundaries

Use your own local installation and data or systems you have explicit permission to test. Do not run automated scans, denial-of-service tests, credential attacks, or social engineering against SiteCMD's public services or other users. Report a suspected availability problem privately without disrupting the service.

Coordination and disclosure

The desktop repository policy targets an initial acknowledgment within three business days. The hosted-service policy commits to acknowledgment and triage without a fixed response deadline. Coordinate public disclosure with the maintainers so users have a fix or mitigation available; this page does not impose a separate fixed disclosure deadline.

The repository security policy governs good-faith research and does not authorize illegal access or testing of third-party services.

Published advisories

Check the SiteCMD security advisories for published notices and affected versions. Use the latest supported release and follow any advisory-specific mitigation instructions.