Description
A critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints.
Recommendation
Update the @samanhappy/mcphub package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.12.15
- Patched version(s): 0.12.15
References
Could your website be exposed too?
SmartScanner can check your website for @samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Imperson and gives you actionable findings to investigate.
Start a free scanRelated Issues
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user - CVE-2026-34524
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818


