Korso · Vulnerability Disclosure

Korso Vulnerability Disclosure

Vulnerability disclosure

Korso publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceAgentsModel Context ProtocolDeveloper ToolsOpen SourceAgent CoordinationY Combinator
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@korsoai.com
Contact
https://github.com/Korso-AI/shepherd/security/advisories/new

Source

Vulnerability Disclosure

korso-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://github.com/Korso-AI/Shepherd/blob/main/SECURITY.md
note: >-
  The automated probe reported a hit on https://korsoai.com/vulnerability-disclosure, but that path is
  the korsoai.com single-page-app catch-all, which returns HTTP 200 with the "Sign in - Korso Console"
  shell for ANY unknown path. That was a false positive and has been replaced with the real, verified
  policy published as SECURITY.md in the Shepherd repository.
policy:
- https://github.com/Korso-AI/Shepherd/blob/main/SECURITY.md
contact:
- security@korsoai.com
- https://github.com/Korso-AI/shepherd/security/advisories/new
preferred_channel: GitHub Security Advisories
bug_bounty: false
public_disclosure_program: null
response_targets:
  acknowledgement: 3 business days
  initial_assessment_and_severity: 7 business days
  remediation: coordinated disclosure timeline agreed with the reporter
scope:
- packages/hub
- packages/mcp-server
- packages/shared
- packages/ui
- Korso-hosted platform front-end/BFF and auth layer (separate non-public repo; reports accepted through
  the same channels)
supported_versions: >-
  Security fixes are applied to the latest release on the main branch. Users are advised to run the most
  recent published version of @korso/shepherd and @korso/shepherd-ui.
credits_reporters: true
evidence:
- source: https://raw.githubusercontent.com/Korso-AI/Shepherd/main/SECURITY.md
  kind: security policy
  status: 200
  keywords:
  - report a vulnerability
  - do not open a public github issue
  - security@korsoai.com
  - github security advisories
- source: https://korsoai.com/.well-known/security.txt
  kind: security.txt
  status: 404