MEDIUM
GHSA-9vq7-9h42-j88h
MCPHub has an authentication bypass
Quick fix
GHSA-9vq7-9h42-j88h — @samanhappy/mcphub: upgrade to the fixed version with the command below.
npm install @samanhappy/mcphub@0.11.0Details
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Are you affected?
Enter the version of the package you're using.