← Volver al buscador de CVEs

CVE-2025-13822

MCPHub

Descripción

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.

CVSS 5.3EPSS 0.35300000000000004%Riesgo 0.55
Ver fuente
Publicación
2026-04-14 11:16:24
Versiones afectadas
<0.11.0
Tipo
Core software
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X