Security fixes are applied to the latest code on main.
Do not open a public issue for a suspected security vulnerability.
Use GitHub's private security advisory flow:
https://github.com/Serbyte-Development/image-search-mcp/security/advisories/new
Include the affected component, reproduction steps, impact, and any suggested mitigation. Do not include real provider API keys or other credentials in the report.