Report privately through GitHub's security advisory form rather than opening a public issue.
Expect an acknowledgement within a week. This is maintained on a best-effort basis alongside other work, so a fix may take longer than that — I will say where things stand rather than go quiet.
The latest released version. This is a young package; there are no long-term support branches.
The core package has no runtime dependencies and makes no network calls, which removes most of the usual surface. Things worth reporting:
- Anything that executes code or touches the filesystem while evaluating company data. The engine reads plain dicts and should never do either.
- A crash or hang from malformed input — deeply nested structures, enormous numbers, unusual types.
These should raise
ValuationError, not take the process down. - A
BenchmarkProviderimplementation in this repository that can be made to leak or fetch something unexpected. - Anything in the optional MCP server that lets a caller reach beyond the four documented tools.
- Valuation figures being wrong for your company. These are simplified textbook methods and their limitations are documented on every result. A number you disagree with is a modelling disagreement — open a normal issue, ideally with a worked example from the literature.
- The default benchmark data being unrealistic. It is deliberately placeholder data, labelled as such on every valuation that uses it.
- Third-party vulnerabilities in the optional
mcpdependency — report those upstream.
Nothing in this package transmits, stores or logs the data you pass it. Valuation inputs stay in memory for the duration of the call.
The MCP server is the one thing to think about: it hands results to whatever model is connected, and that model's provider will see them. If you are valuing companies under NDA, that matters more than anything in this file.
openvaluation · MIT licensed