Vulnerabilities/

@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Imperson

Severity:
High

Description

A critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints.

Recommendation

Update the @samanhappy/mcphub package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@samanhappy/mcphub
Anything's wrong? Let us know Last updated on May 14, 2026