CVE-2025-13822

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
14/04/2026
Last modified:
14/04/2026

Description

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.