| CVE ID | CVE-2025-13822 |
| Publication date | 14 April 2026 |
| Vendor | MCPHub |
| Product | MCPHub |
| Vulnerable versions | All before 0.11.0 |
| Vulnerability type (CWE) | Authorization Bypass Through User-Controlled Key (CWE-639) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in MCPHub project and participated in coordination of its disclosure.
The vulnerability CVE-2025-13822: MCPHub in versions below 0.11.0 is vulnerable to Authentication Bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.
Credits
We thank Eryk Winiarz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.