Please report security issues privately through GitHub's advisory form:
https://github.com/jacob-bd/gemini-notebook-mcp-cli/security/advisories/new
Please do not open a public issue for anything that looks exploitable. If you are not sure whether something qualifies, report it privately and we will sort it out together.
Helpful things to include, though none of them are required:
- The version or commit you reviewed
- The affected file and line
- What an attacker gains, stated as narrowly as you can
- A proof of concept, if you have one
- A suggested fix, if you have one
| Stage | Target |
|---|---|
| First response | 3 business days |
| Triage and severity decision | 7 business days |
| Fix released for High or Critical | 14 days from triage |
| Fix released for Low or Medium | Next scheduled release |
This is a personal open source project, not a funded product, so these are targets rather than guarantees. If a report goes quiet, please ping the advisory thread.
Only the latest released version gets security fixes. Please upgrade before reporting an issue against an older release.
| Version | Supported |
|---|---|
| 0.11.x | Yes |
| < 0.11 | No |
In scope:
- The
notebooklm-mcpMCP server and its tools - The
nlmCLI - Credential handling, file writes, and the authentication flows
- Setup instructions in
docs/that create a security boundary
Out of scope:
- Vulnerabilities in Google's services. Please report those to Google.
- Chrome DevTools Protocol having no authentication. That is Chrome's design.
- Anything that requires an attacker to already have your Google session cookies.
Reporters get credited in CHANGELOG.md and in the published advisory unless
they ask not to be. Please say so in the report if you would rather stay
anonymous.
There is no bug bounty program and no payment. Reports are welcome anyway, and they get taken seriously.