Only the latest released version of ipinfo-mcp-server receives security updates.
Please report security vulnerabilities by email to support@ipinfo.io. Do not open a public GitHub issue for security reports.
If you want to encrypt your report, use our PGP key: https://ipinfo.io/.well-known/pgp-key.txt
Include as much detail as you can: affected version, reproduction steps, and potential impact.
- We acknowledge reports within 2 business days.
- We aim to provide an assessment within 5 business days.
- We aim to ship a fix for confirmed vulnerabilities within 30 days, and we follow a 90-day coordinated disclosure window.
We will credit reporters in the release notes unless asked otherwise.