Vulnerabilità ed exploit · Attacco ad app web

MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged

MCPHub is treating some endpoints as trusted when they are not. In versions below 0.11.0, missing authentication middleware lets an unauthenticated user perform actions as other users and inherit their privileges.

CERT Polska says the flaw is CVE-2025-13822 and affects MCPHub below 0.11.0. The issue is an authentication bypass, not credential theft, so the danger is direct privilege abuse on exposed endpoints.

The risk persists anywhere MCPHub is deployed with those endpoints reachable. Fixing the version closes the gap, but any action already taken under another user’s identity still needs review.

4 fonti · 20 apr

CVE-2025-13822

NVD KEV

EPSS 0.4% (27º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-20

Every edition of this story: MCPHub Auth Bypass Lets Unauthenticated Users Act Privileged

Altro da oggi