Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9vq7-9h42-j88h | MCPHub has an authentication bypass |
Fri, 01 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcphubx
Mcphubx mcphub |
|
| CPEs | cpe:2.3:a:mcphubx:mcphub:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mcphubx
Mcphubx mcphub |
|
| Metrics |
cvssV3_1
|
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcphub
Mcphub mcphub |
|
| Vendors & Products |
Mcphub
Mcphub mcphub |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges. | |
| Title | Authentication bypass in MCPHub | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-04-14T13:14:16.888Z
Reserved: 2025-12-01T13:03:39.659Z
Link: CVE-2025-13822
Updated: 2026-04-14T13:08:50.784Z
Status : Analyzed
Published: 2026-04-14T11:16:24.300
Modified: 2026-05-01T15:44:18.247
Link: CVE-2025-13822
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:30:36Z
Github GHSA