Vulnerability library
Security checkOctober 09, 2025

MCPHub has an Improper Authorization vulnerability via its handleSseConnection function

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@samanhappy/mcphub

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnection of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 0.9.10

References

Could your website be exposed too?

SmartScanner can check your website for MCPHub has an Improper Authorization vulnerability via its handleSseConnection function and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated October 09, 2025