Vulnerabilità ed exploit · Attacco ad app web
MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged MCPHub is treating some endpoints as trusted when they are not. In versions below 0.11.0 , missing authentication middleware lets an unauthenticated user perform actions as other users and inherit their privileges.
CERT Polska says the flaw is CVE-2025-13822 and affects MCPHub below 0.11.0 . The issue is an authentication bypass, not credential theft, so the danger is direct privilege abuse on exposed endpoints.
The risk persists anywhere MCPHub is deployed with those endpoints reachable. Fixing the version closes the gap, but any action already taken under another user’s identity still needs review.
4 fonti · 20 apr
CVE-2025-13822 NVD KEV
EPSS 0.4% (27º percentile).
Cronologia Fonti 20 apr The Hacker News
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
MCP design flaw enables RCE across 7,000+ servers and 150M downloads, impacting AI SDKs and supply chains.
originale 17 apr The Register Security
MCP 'design flaw' puts 200k servers at risk: Researcher
: Bug or feature?
originale 16 apr Infosecurity Magazine
Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads
Ox Security claims as many as 200,000 servers are exposed by newly discovered MCP vulnerability
originale Part of the PlainSec briefing for 2026-04-20
Every edition of this story: MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged MCPHub is treating some endpoints as trusted when they are not. In versions below 0.11.0 , missing authentication middleware lets an unauthenticated user perform actions as other users and inherit their privileges.
CERT Polska says the flaw is CVE-2025-13822 and affects MCPHub below 0.11.0 . The issue is an authentication bypass, not credential theft, so the danger is direct privilege abuse on exposed endpoints.
The risk persists anywhere MCPHub is deployed with those endpoints reachable. Fixing the version closes the gap, but any action already taken under another user’s identity still needs review.
4 fonti · 20 apr
CVE-2025-13822 NVD KEV
EPSS 0.4% (27º percentile).
Cronologia Fonti 20 apr The Hacker News
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
MCP design flaw enables RCE across 7,000+ servers and 150M downloads, impacting AI SDKs and supply chains.
originale 17 apr The Register Security
MCP 'design flaw' puts 200k servers at risk: Researcher
: Bug or feature?
originale 16 apr Infosecurity Magazine
Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads
Ox Security claims as many as 200,000 servers are exposed by newly discovered MCP vulnerability
originale Part of the PlainSec briefing for 2026-04-20
Every edition of this story: MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged
Altro da oggi