VulnerabilityAnalyzed
CVE-2025-13822
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass.
MEDIUM 5.3EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- mcphubx/mcphub
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2026/04/CVE-2025-13822Third Party Advisory
- https://github.com/samanhappy/mcphubProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.