Vulnerabilities in samanhappy
11 resultsVexday analysis
A samanhappy apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma delas em exploração ativa ou com severidade crítica. O risco concentra-se em falhas de autenticação (CWE-287), mas a ausência de publicações recentes e de atividade exploratória indica que o panorama de ameaças para este fornecedor permanece estável.
CVE-2025-11285MEDIUMsamanhappy MCPHub serverController.ts os command injectionEPSS 7.8%CVE-2025-11287MEDIUMsamanhappy MCPHub sseService.ts handleSseConnectionfunction improper authenticationEPSS 0.6%CVE-2026-79743MEDIUMMCPHub: Path Traversal via Malicious MCPB Manifest NameEPSS 0.4%CVE-2026-79748CRITICALMCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args)EPSS 0.3%CVE-2025-11286MEDIUMsamanhappy MCPHub MCPRouter Service serverController.ts server-side request forgeryEPSS 0.3%CVE-2026-79744HIGHMCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin Rewrite Global Security ConfigurationEPSS 0.3%CVE-2026-79749HIGHMCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL ValidationEPSS 0.3%CVE-2026-79750HIGHMCPHub authenticated horizontal IDOR: any non-admin user executes tools on other users' MCP servers (cross-tenant file read + SSRF)EPSS 0.3%CVE-2026-79746HIGHMCPHub: Server-scoped bearer key gains access to an entire group via partial (any-overlap) server matchingEPSS 0.3%CVE-2026-79745HIGHMCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorized Tampering of Globally-Served Templates/Resources)EPSS 0.2%CVE-2026-79747HIGHMCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy + transport dial)EPSS 0.2%