# Security Policy

## Supported Versions

| Version | Supported |
| ------- | --------- |
| 1.139.x | Yes       |
| < 1.139 | No        |

## Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

1. **Do not** open a public GitHub issue.
2. Email the maintainer or use [GitHub Security Advisories](https://github.com/gaopengbin/cesium-mcp/security/advisories/new) to report privately.
3. Include a description of the vulnerability, steps to reproduce, and potential impact.

We will acknowledge receipt within 48 hours and aim to release a fix within 7 days for critical issues.
