Server-Side Request Forgery Vulnerability in MCPHub by Samanhappy
CVE-2026-79747
7.1HIGH
What is CVE-2026-79747?
MCPHub, a platform for managing multiple MCP servers and APIs, is vulnerable to a server-side request forgery (SSRF) due to improper validation of user-submitted server URLs. Authenticated non-admin users prior to version 1.0.32 can register servers pointing to arbitrary URLs, allowing the hub to make unfiltered server-side requests to these locations. This vulnerability exposes sensitive data by relaying the response body back to the caller via the OpenAPI proxy, while also permitting blind requests through the SSE/streamable-http transport. This issue has been resolved in version 1.0.32.
Affected Version(s)
mcphub < 1.0.32
