Skip to content

Security: codejavu-llc/moppscan

SECURITY.md

Security Policy

Reporting a vulnerability

Report vulnerabilities in MoppScan privately through a GitHub Security Advisory. Do not open a public issue or include real target credentials, cookies, or unredacted evidence in a discussion.

Please include the affected version, environment, minimal reproduction, impact, and any suggested mitigation. Maintainers aim to acknowledge a report within three business days and will coordinate disclosure after a fix is available.

Supported versions

Version Support
2.1 release candidates Security fixes during the public RC cycle
Latest stable release Security and critical bug fixes
Older releases Upgrade required

Responsible use

MoppScan is dual-use software for systems the operator owns or is explicitly authorized to assess. Misuse may be illegal.

  • TLS verification is enabled by default.
  • Client-side canary scans add query/hash parameters that a target may log.
  • Gadget execution requires an explicit CLI/MCP gate.
  • SSPP requires confirmation, changes prototype-derived response properties, attempts mitigation, verifies the observable reset, and stops if verification fails. It cannot promise restoration of an application's exact original absent/default property.
  • The irreversible immutable-prototype technique and denial-of-service payloads are not implemented.
  • MCP network access is operator-scoped and private networks are blocked by default.

Read the complete threat model before enabling MCP active tools or SSPP.

There aren't any published security advisories