PT-2026-83946 · Mcphub · Mcphub

·

CVE-2026-79748

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MCPHub versions prior to 0.12.15
Description Authenticated non-admin users can execute arbitrary processes as the server's OS user, which is often root in Docker, npx, or systemd deployments. This occurs because the 'POST /api/servers' and 'PUT /api/servers/:name' endpoints lack authorization checks and do not sanitize the command and args fields before passing them to the child process.spawn function.
Recommendations Update to version 0.12.15.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79748
GHSA-MX89-JJX9-GJR8

Affected Products

Mcphub