VORANT. Threat Intelligence Sign in Get the full feed

MCPHub versions below 0.11.0 contain an authentication bypass vulnerability…

high vulnerability

MCPHub versions below 0.11.0 contain an authentication bypass vulnerability (CVE-2025-13822) allowing unauthenticated attackers to impersonate users and abuse their privileges.

CERT Polska coordinated the disclosure of CVE-2025-13822, an authentication bypass vulnerability affecting MCPHub versions prior to 0.11.0. The flaw stems from certain endpoints lacking proper authentication middleware protection, enabling unauthenticated attackers to execute actions on behalf of legitimate users while leveraging their associated privileges.

The vulnerability was responsibly reported by researcher Eryk Winiarz and follows CERT Polska's coordinated vulnerability disclosure process. Organizations running affected MCPHub versions should prioritize upgrading to version 0.11.0 or later to remediate this authentication control weakness.

The authentication bypass represents a complete failure of access control on specific endpoints, allowing privilege escalation and unauthorized actions without any credential requirements. The impact depends on MCPHub deployment contexts and the privileges available to compromised user accounts.

Mentioned in this report

Vulnerabilities CVE-2025-13822

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13822

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free