MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
References
| Link | Resource |
|---|---|
| https://cert.pl/en/posts/2026/04/CVE-2025-13822 | Third Party Advisory |
| https://github.com/samanhappy/mcphub | Product |
Configurations
History
01 May 2026, 15:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mcphubx mcphub
Mcphubx |
|
| CPE | cpe:2.3:a:mcphubx:mcphub:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| References | () https://cert.pl/en/posts/2026/04/CVE-2025-13822 - Third Party Advisory | |
| References | () https://github.com/samanhappy/mcphub - Product |
14 Apr 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 11:16
Updated : 2026-05-01 15:44
NVD link : CVE-2025-13822
Mitre link : CVE-2025-13822
CVE.ORG link : CVE-2025-13822
JSON object : View
Products Affected
mcphubx
- mcphub
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
