Report vulnerabilities in MoppScan privately through a GitHub Security Advisory. Do not open a public issue or include real target credentials, cookies, or unredacted evidence in a discussion.
Please include the affected version, environment, minimal reproduction, impact, and any suggested mitigation. Maintainers aim to acknowledge a report within three business days and will coordinate disclosure after a fix is available.
| Version | Support |
|---|---|
| 2.1 release candidates | Security fixes during the public RC cycle |
| Latest stable release | Security and critical bug fixes |
| Older releases | Upgrade required |
MoppScan is dual-use software for systems the operator owns or is explicitly authorized to assess. Misuse may be illegal.
- TLS verification is enabled by default.
- Client-side canary scans add query/hash parameters that a target may log.
- Gadget execution requires an explicit CLI/MCP gate.
- SSPP requires confirmation, changes prototype-derived response properties, attempts mitigation, verifies the observable reset, and stops if verification fails. It cannot promise restoration of an application's exact original absent/default property.
- The irreversible immutable-prototype technique and denial-of-service payloads are not implemented.
- MCP network access is operator-scoped and private networks are blocked by default.
Read the complete threat model before enabling MCP active tools or SSPP.