GHSA-wf8q-wvv8-p8jf
CRITICALA critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints. The server accepts a username from the URL path parameter and creates an internal user session without any database validation, token verification, or authentication check. The source code itself ack
- Affected
- < 0.12.15, >=0, <0.12.15
- Fixed in
- 0.12.15
- Weakness
- CWE-290
- Published
- 2026-05-14
- Source
- github