Unauthorized Access in MCPHub API Controller by Samanhappy
CVE-2026-79745
7.1HIGH
What is CVE-2026-79745?
Prior to version 1.0.32, MCPHub's built-in prompt and resource controllers lacked essential role checking, allowing non-admin users to create, overwrite, and shadow global prompt templates and resources. These vulnerabilities stem from the mutating POST/PUT routes that bypass admin verification. The unauthorized modifications lead to integrity violations, impacting all users and enabling potential stored prompt injections into LLM sessions as a downstream effect. This serious oversight presents significant risks to data integrity within shared resources, making prompt updates a shared concern. The issue was addressed in version 1.0.32.
Affected Version(s)
mcphub < 1.0.32
