Please report vulnerabilities privately via GitHub's private vulnerability reporting ("Report a vulnerability" under the repo's Security tab).
Do not open a public issue for a security problem.
This applies to the @ora-ai/webmcp-bridge npm package as well — bridge
bugs that let a page's tools escape their intended scope are security
reports, not bug reports.
Only the latest published version of @ora-ai/webmcp-bridge receives
security fixes.