CVE-2025-13822 is an authentication bypass vulnerability affecting MCPHub versions prior to 0.11.0, where certain endpoints lack proper authentication middleware protections, enabling unauthenticated attackers to execute actions with the privileges of other users. The vulnerability presents a moderate risk with a FAUCET Risk Score of 32.0/100, though specific CVSS metrics are not yet available. The attack vector appears to be network-based and likely requires minimal complexity for exploitation. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.0005 indicates relatively low probability of exploitation within the next 30 days, though organizations running vulnerable MCPHub versions should prioritize upgrading to version 0.11.0 or later to remediate this authentication control bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.11.0CPE matchmatch criteria | cpe:2.3:a:mcphubx:mcphub:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.