Security fixes are provided for the latest released version of mcp-vmanomaly. Upgrade to the
latest release before reporting an issue that may already have been fixed.
Report suspected vulnerabilities privately to security@victoriametrics.com. Do not open a public GitHub issue for an undisclosed vulnerability.
Include the affected version, transport and deployment topology, the enabled tool/resource policy, reproducible steps, and the expected impact. Remove live credentials, tenant data, and other secrets from logs or examples before sending them.