Mcphubx
Mcphubx Mcphub: vulnerabilidades y CVE
Mcphubx Mcphub tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses14
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94047 | Baja (2.1) | 0.43% | — | 20 sept 2026 | A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint.… |
| CVE-2026-90474 | Alta (7.6) | 0.55% | — | 12 sept 2026 | MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who… |
| CVE-2026-79750 | Alta (7.7) | 0.43% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to… |
| CVE-2026-79749 | Alta (7.6) | 0.45% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, MCPHub's SSRF guard in… |
| CVE-2026-79748 | Crítica (9.9) | 0.64% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT… |
| CVE-2026-79747 | Alta (7.1) | 0.30% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user… |
| CVE-2026-79746 | Alta (8.1) | 0.43% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with… |
| CVE-2026-79745 | Alta (7.1) | 0.44% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in prompt and resource… |
| CVE-2026-79744 | Alta (8.8) | 0.56% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config… |
| CVE-2026-79743 | Media (6.9) | 0.54% | — | 31 ago 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Upload Handler… |
| CVE-2025-13822 | Media (5.3) | 0.35% | — | 14 abr 2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users… |
| CVE-2025-11287 | Media (5.5) | 0.56% | — | 5 oct 2025 | A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src/services/sseService.ts. Such manipulation leads to improper… |
| CVE-2025-11286 | Baja (2) | 0.31% | — | 5 oct 2025 | A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controllers/serverController.ts of the component MCPRouter Service. This manipulation of the argument… |
| CVE-2025-11285 | Baja (2.1) | 7.8% | — | 5 oct 2025 | A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of the argument command/args results in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.