Improper File Handling Vulnerability in MCPHub by Saman Happy
CVE-2026-79743

6.9MEDIUM

Key Information:

Vendor

Samanhappy

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-79743?

MCPHub, a centralized management tool for MCP servers, contains a vulnerability in its File Upload Handler that affects versions prior to 0.12.13. The handler improperly processes the name field from a ZIP file's manifest.json, allowing an attacker to craft a malicious file that results in arbitrary file extraction on the server. This vulnerability also allows potential deletion of directories due to the unsanitized handling of paths, posing serious security risks. The issue has been resolved in version 0.12.13, which implements necessary input validation to mitigate the risk.

Affected Version(s)

mcphub < 0.12.13

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.