Server-Side Request Forgery Vulnerability in MCPHub by Samanhappy
CVE-2026-79747

7.1HIGH

Key Information:

Vendor

Samanhappy

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-79747?

MCPHub, a platform for managing multiple MCP servers and APIs, is vulnerable to a server-side request forgery (SSRF) due to improper validation of user-submitted server URLs. Authenticated non-admin users prior to version 1.0.32 can register servers pointing to arbitrary URLs, allowing the hub to make unfiltered server-side requests to these locations. This vulnerability exposes sensitive data by relaying the response body back to the caller via the OpenAPI proxy, while also permitting blind requests through the SSE/streamable-http transport. This issue has been resolved in version 1.0.32.

Affected Version(s)

mcphub < 1.0.32

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.