Skip to content

Security: putervision/state-memory-mcp

Security

SECURITY.md

Security Policy

state-memory-mcp handles local workspace workflow state, decision graphs, and database storage. We take security seriously.


Supported Versions

Version Supported
v0.9.x
v0.8.x
< 0.8.0

Reporting a Vulnerability

If you discover a security vulnerability in state-memory-mcp (e.g., path traversal, unsafe SQL execution, or database file permissions exposure), please report it responsibly:

  1. Do NOT open a public GitHub issue.
  2. Send an email to security@putervision.com or report via GitHub Security Advisory.
  3. Include detailed steps to reproduce, impact analysis, and proof-of-concept if available.

Our Commitment

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We will provide a regular status update until the vulnerability is addressed.
  • A patched release will be published to npm promptly once verified.

Disclaimer & Limitation of Liability

This software is provided "as is", without warranty of any kind, express or implied. Under no circumstances shall the authors or contributors be liable for any database corruption, Git repository modification, data loss, or other issues resulting from execution. Always backup your database files before performing destructive operations.

There aren't any published security advisories