PT-2026-96004 · Samanhappy · Mcphub

·

CVE-2026-94047

·

Published

2026-09-20

·

Updated

2026-09-22

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions samanhappy MCPHub versions prior to 1.0.33
Description Improper privilege management exists within the Template Import Endpoint. The issue resides in the importTemplate() function located in the src/services/templateService.ts file, allowing for remote exploitation.
Recommendations Upgrade to version 1.0.33. As a temporary mitigation, restrict access to the importTemplate() function.

Exploit

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94047

Affected Products

Mcphub