Description
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Recommendation
Update the @samanhappy/mcphub package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.11.0
- Patched version(s): 0.11.0
References
Could your website be exposed too?
SmartScanner can check your website for MCPHub has an authentication bypass and gives you actionable findings to investigate.
Start a free scanRelated Issues
- MCPHub has an Improper Authorization vulnerability via its handleSseConnection function - CVE-2025-11287
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
- Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments - CVE-2025-13877
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200


