top of page
perceptive_background_267k.jpg

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 21:03:29

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Emerging Technologies

MCPHub, a unified hub for managing and orchestrating MCP servers and APIs, contains a critical missing authorization vulnerability prior to version 1.0.32. The built-in prompt and resource controllers perform no role checking on mutating POST/PUT routes under /api/prompts* and /api/resources*. These routes are attached to an authenticated router but lack an admin gate, and handlers never read req.user to verify permissions. DAO singletons written by these endpoints are consulted first for every session, ahead of any connected MCP server. This allows any authenticated non-admin user to create, overwrite, or shadow global prompt templates and resources served to all users. The primary impact is unauthorized integrity violation of globally-served records, with stored prompt injection into other users' LLM sessions as a downstream consequence. The vulnerability has been patched in MCPHub version 1.0.32.

Technical details

Mitigation steps:

Affected products:

MCPHub

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page