CVE-2025-13822
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
14/04/2026
Last modified:
14/04/2026
Description
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM



