Skip to content

Security: a4webdev/tiacommander-mcp

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in TiaCommander, please report it responsibly. Do not open a public GitHub issue for security vulnerabilities.

How to Report

Email info@tiacommander.com with:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (optional)

What to Expect

  • Acknowledgment within 48 hours of your report
  • Assessment and severity classification within 5 business days
  • Resolution timeline communicated based on severity
  • Credit in the release notes (if desired) once the fix is published

Scope

This policy covers:

  • TiaCommander MCP Server (the .exe distributed via this repository)
  • TiaCommander Manager (the configuration GUI)
  • The TiaCommander website (tiacommander.com)

Out of Scope

  • Siemens TIA Portal vulnerabilities (report to Siemens ProductCERT)
  • Third-party MCP client vulnerabilities (report to the respective client)

Supported Versions

Version Supported
Latest release Yes
Previous releases Security fixes only

There aren't any published security advisories