MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
References
| Link | Resource |
|---|---|
| https://cert.pl/en/posts/2026/04/CVE-2025-13822 | Third Party Advisory |
| https://github.com/samanhappy/mcphub | Product |
Configurations
History
No history.
Information
Published : 2026-04-14 11:16
Updated : 2026-09-03 03:15
NVD link : CVE-2025-13822
Mitre link : CVE-2025-13822
CVE.ORG link : CVE-2025-13822
JSON object : View
Products Affected
mcphubx
- mcphub
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
