Home
MEDIUM: 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 0.11.0
affected
Description
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 0.11.0
Credits
Eryk Winiarz
References
github.com/samanhappy/mcphub
cert.pl/en/posts/2026/04/CVE-2025-13822