Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

MCPHub has an authentication bypass

GHSA-9vq7-9h42-j88h · CVE-2025-13822

Published · Modified

Description

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.

Ready to move

Start Securing

Free, no credit card | First findings in minutes