Pentest-AI
Project

Report a security issue

A private route for reproducible vulnerabilities in Pentest-AI.

Updated 12 September 2026

Report privately

For vulnerabilities in the open-source CLI or MCP server, open a private GitHub Security Advisory.

Alternatively, email [email protected] with the subject [SECURITY] short description. Do not post vulnerabilities, private evidence or credentials in a public issue.

Include enough to reproduce

  • The affected version and commit, if known.
  • The component or command involved.
  • Minimal reproduction steps in a test environment you control.
  • The impact observed and any suggested fix.
  • Your preferred name or handle for credit, if you want it.

Scope and limits

Reports about the CLI, MCP server, scope enforcement, authentication handling, tool wrappers or stored evidence belong in the repository's security process. For a problem with this website, use the email channel and identify the URL.

Report defects in third-party tools and infrastructure to their maintainers. Do not perform destructive tests, denial-of-service, social engineering or access to someone else's data. The project does not offer a paid bounty program.

If you encounter private data or unexpected access, stop and contact the owner. This page is not blanket authorization to test arbitrary project-related hosts.

Response process

The repository's policy commits to acknowledgment within three business days, initial triage within seven business days and coordinated disclosure for confirmed vulnerabilities. Credit can be included in release notes on request.

Read the repository security policy

Security contact file

Machine-readable contact details are available at security.txt. A public contact file does not change the authorized scope of a test.

Found something unclear?Open an issue ↗