PT-2026-96004 · Samanhappy · Mcphub
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
samanhappy MCPHub versions prior to 1.0.33
Description
Improper privilege management exists within the Template Import Endpoint. The issue resides in the
importTemplate() function located in the src/services/templateService.ts file, allowing for remote exploitation.Recommendations
Upgrade to version 1.0.33.
As a temporary mitigation, restrict access to the
importTemplate() function.Exploit
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcphub