Vulnerabilities/

MCPHub has an Improper Authorization vulnerability via its handleSseConnection function

Severity:
Medium

Description

A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnection of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@samanhappy/mcphub
Anything's wrong? Let us know Last updated on October 09, 2025