5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether @samanhappy/mcphub is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-79743
MCPHub has Path Traversal via Malicious MCPB Manifest Name
CRITICAL 9.1
GHSA-wf8q-wvv8-p8jf
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
UNKNOWN
CVE-2025-13822
MCPHub has an authentication bypass
UNKNOWN
CVE-2025-11287
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
UNKNOWN
CVE-2025-11285
MCPHub's ServerController is vulnerable to Command Injection
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes