CVE-2025-13822
EPSS 0.4% (27º percentile).
Vulnerabilità · 163 giorni fa
MCPHub is treating some endpoints as trusted when they are not. In versions below 0.11.0, missing authentication middleware lets an unauthenticated user perform actions as other users and inherit their privileges.
CERT Polska says the flaw is CVE-2025-13822 and affects MCPHub below 0.11.0. The issue is an authentication bypass, not credential theft, so the danger is direct privilege abuse on exposed endpoints.
The risk persists anywhere MCPHub is deployed with those endpoints reachable. Fixing the version closes the gap, but any action already taken under another user’s identity still needs review.
EPSS 0.4% (27º percentile).
4 fonti che coprono questa storia
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
MCP design flaw enables RCE across 7,000+ servers and 150M downloads, impacting AI SDKs and supply chains.
MCP 'design flaw' puts 200k servers at risk: Researcher
: Bug or feature?
Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads
Ox Security claims as many as 200,000 servers are exposed by newly discovered MCP vulnerability
Vulnerability in MCPHub software
Authorization bypass vulnerability (CVE-2025-13822) has been found in MCPHub project.
Part of the PlainSec briefing for 2026-04-20