Security Advisories for @samanhappy/mcphub in npm
Critical
3 months ago
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
npm
@samanhappy/mcphub
Moderate
10 months ago
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
npm
@samanhappy/mcphub
Low
10 months ago
MCPHub's ServerController is vulnerable to Command Injection
npm
@samanhappy/mcphub