VORANT. Threat Intelligence Sign in Get the full feed

MCPHub auth bypass lets attackers hijack user privileges

medium vulnerability

MCPHub versions below 0.11.0 contain an authentication bypass flaw (CVE-2025-13822) allowing unauthenticated attackers to impersonate users and abuse their privileges.

CERT Polska disclosed CVE-2025-13822, an authentication bypass vulnerability in MCPHub affecting all versions prior to 0.11.0. The flaw stems from endpoints that lack authentication middleware protection, enabling unauthenticated attackers to execute actions as legitimate users and leverage their privileges without proper authorization checks.

The vulnerability was responsibly reported by Eryk Winiarz and coordinated through CERT Polska's disclosure process. Organizations running affected MCPHub versions should upgrade to 0.11.0 or later to remediate the issue. The advisory provides minimal technical detail beyond the authentication bypass mechanism, and there is no indication of active exploitation at the time of disclosure.

Mentioned in this report

Vulnerabilities CVE-2025-13822

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13822

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free