MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
- Severity:
- Medium
Description
A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnection of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.9.10
References
Related Issues
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200
- MCPHub has an authentication bypass - CVE-2025-13822
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
You might also like:
- Tags:
- npm
- @samanhappy/mcphub
Anything's wrong? Let us know Last updated on October 09, 2025


