Description
A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnection of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.9.10
References
Could your website be exposed too?
SmartScanner can check your website for MCPHub has an Improper Authorization vulnerability via its handleSseConnection function and gives you actionable findings to investigate.
Start a free scanRelated Issues
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200
- MCPHub has an authentication bypass - CVE-2025-13822
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability


