Mcphubx is a narrowly scoped vendor with a concentrated product footprint centered on the mcphub platform, an integration or hub-style component likely positioned within broader infrastructure. The vendor's disclosures cluster around control-plane and authentication weaknesses—including authorization bypasses, improper authentication, command injection, OS command injection, and server-side request forgery—patterns that reflect a networked service's exposure to both direct manipulation and indirect request-pivoting attacks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mcphubx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11287CRITICAL A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src/services/sseService.ts. Such m | Oct 5, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-11285HIGH A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation | Oct 5, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-13822MEDIUM MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perfo | Apr 14, 2026 | 5.3 | 21 | NO | NO |
CVE-2025-11286MEDIUM A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controllers/serverController.ts of the component MCPRouter Service. T | Oct 5, 2025 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mcphubx.
Media articles that mention a CVE ID that affects a product developed by Mcphubx — matched by CVE ID, not by vendor name.