Repository navigation
Security: samanhappy/mcphub
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Potential exposure of process environment values through MCP server configuration expansionGHSA-547h-r8jj-9wmc published
Oct 3, 2026 by samanhappyModerate -
Unauthenticated upstream OAuth callback state bypass binds any server to an attacker accountGHSA-vc28-27px-x492 published
Oct 3, 2026 by samanhappyHigh -
Authenticated non-admin can overwrite admin-installed MCPB executables and achieve stored RCEGHSA-xf2m-3c3x-53vp published
Sep 27, 2026 by samanhappyHigh -
SSRF guard bypass via DNS rebinding: assertSafeUrl validates the resolved IP but connects by hostnameGHSA-j6m9-g2r5-28rw published
Oct 4, 2026 by samanhappyModerate -
SSRF via unvalidated OAuth discovery/registration/metadata URLs in server configGHSA-xvpg-v6pr-xc32 published
Sep 2, 2026 by samanhappyModerate -
Activity-log IDOR: non-admin reads and wipes all users' tool-call history (DB mode)GHSA-94jf-cmwm-q3p5 published
Sep 2, 2026 by samanhappyHigh -
Missing authorization on log routes lets any non-admin read and wipe system logsGHSA-cvw6-m995-5vvv published
Sep 2, 2026 by samanhappyModerate -
Server-scoped bearer key gains access to an entire group via partial (any-overlap) server matchingGHSA-454m-4vm6-842f published
Aug 22, 2026 by samanhappyHigh -
Template export skips the ownership filter every other read path usesGHSA-p589-v5cm-35qg published
Aug 23, 2026 by samanhappyModerate -
Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorized Tampering of Globally-Served Templates/Resources)GHSA-6cvf-cfch-4g7m published
Aug 23, 2026 by samanhappyHigh
Learn more about advisories related to samanhappy/mcphub in the GitHub Advisory Database