Home

Description

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.

PUBLISHED Reserved 2025-12-01 | Published 2026-04-14 | Updated 2026-04-14 | Assigner CERT-PL




MEDIUM: 5.3CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 0.11.0
affected

Credits

Eryk Winiarz finder

References

github.com/samanhappy/mcphub product

cert.pl/en/posts/2026/04/CVE-2025-13822 third-party-advisory

cve.org (CVE-2025-13822)

nvd.nist.gov (CVE-2025-13822)

Download JSON