# MCPHub Auth Bypass Flaw Disclosed

Published: 2026-04-14 · Severity: medium
Canonical: https://vorant.io/reports/9e159839-86f0-5617-b2b2-5a73c37e0554/mcphub-auth-bypass-flaw-disclosed

> MCPHub versions below 0.11.0 lack authentication on some endpoints, letting unauthenticated attackers act with other users' privileges.

CERT Polska coordinated the disclosure of CVE-2025-13822, an authentication bypass vulnerability affecting the MCPHub project in versions prior to 0.11.0. The flaw stems from certain endpoints not being protected by authentication middleware, which allows an unauthenticated attacker to perform actions on behalf of other users, effectively assuming their privileges.

The vulnerability was reported to CERT Polska by researcher Eryk Winiarz through the organization's coordinated vulnerability disclosure (CVD) process. No evidence of active exploitation is mentioned in the advisory, and the primary recommendation is for affected organizations to upgrade to MCPHub 0.11.0 or later.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13822

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13822

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9e159839-86f0-5617-b2b2-5a73c37e0554/mcphub-auth-bypass-flaw-disclosed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
