Security fixes are released for the latest published minor version of Cortex Docs. Upgrade to the latest patch before you report a problem that might already be fixed.
Use GitHub private vulnerability reporting. Do not open a public issue.
Include the following information:
- The affected package and version
- The required configuration
- Steps or code that reproduce the problem
- The expected effect and the observed effect
- A suggested fix, if you have one
Remove tokens, private API specifications, and personal data from the report.
A maintainer will acknowledge a complete report within five business days. We will share progress while we investigate. We will coordinate disclosure and credit with the reporter.
Reports about generated code, the CLI, the documentation runtime, and generated MCP servers are in scope. Dependency reports must show a practical effect on Cortex Docs or its generated output.