Description
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Recommendation
Update the @samanhappy/mcphub package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.11.0
- Patched version(s): 0.11.0
References
Related Issues
- MCPHub has an Improper Authorization vulnerability via its handleSseConnection function - CVE-2025-11287
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
- Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments - CVE-2025-13877
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200
You might also like:
- Tags:
- npm
- @samanhappy/mcphub
Anything's wrong? Let us know Last updated on April 15, 2026


