@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Imperson
- Severity:
- High
Description
A critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints.
Recommendation
Update the @samanhappy/mcphub package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.12.15
- Patched version(s): 0.12.15
References
Related Issues
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user - CVE-2026-34524
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818
You might also like:
- Tags:
- npm
- @samanhappy/mcphub
Anything's wrong? Let us know Last updated on May 14, 2026


