Only the latest published version receives security fixes.
Use GitHub private vulnerability reporting for vectojs/numera-mcp. Do not
include secrets, private workbooks, or exploit payloads in a public issue.
The server confines all tool paths to its configured root, rejects symlink escapes, limits workbook and range work through the underlying codecs and tool caps, preserves source files, requires optimistic SHA-256 matching, and writes new outputs atomically. It performs no outbound network access.