LOWnpm
GHSA-5q2p-3jg8-2m98· CVE-2025-11285MCPHub's ServerController is vulnerable to Command Injection
Modified: 10/9/2025
package
pkg:npm/%40samanhappy/mcphub
MCPHub's ServerController is vulnerable to Command Injection
Modified: 10/9/2025
MCPHub has an authentication bypass
Modified: 4/15/2026
MCPHub has Path Traversal via Malicious MCPB Manifest Name
Modified: 9/1/2026
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
Modified: 10/9/2025
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
Modified: 5/14/2026