PatchSiren

samanhappy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH samanhappy CVE published 2026-08-31

CVE-2026-79749

PatchSiren debrief for CVE-2026-79749: MCPHub SSRF guard bypass via IPv6 transition addresses. The vulnerability allows an attacker to bypass the SSRF guard using IPv6 transition addresses, potentially leading to unauthorized access to internal infrastructure. MCPHub users and administrators should assess exposure and apply patches to prevent potential SSRF attacks. The custom isBlockedIpv6 function in sr [truncated]

CRITICAL samanhappy CVE published 2026-08-31

CVE-2026-79748

A critical vulnerability in MCPHub, a unified hub for managing multiple MCP servers/APIs, allows any authenticated non-admin user to execute arbitrary commands as the MCPHub server's OS user, commonly root. This issue, patched in version 0.12.15, enables attackers to spawn processes via child_process.spawn without proper authorization or input validation.

HIGH samanhappy CVE published 2026-08-31

CVE-2026-79747

An authenticated non-admin user can register a server pointing at an arbitrary URL and make the hub issue server-side requests to it, with no egress filtering, via MCPHub prior to version 1.0.32. This Server-Side Request Forgery (SSRF) vulnerability allows the hub to issue server-side requests to arbitrary URLs, potentially exposing internal services and allowing for blind SSRF via SSE/streamable-http tra [truncated]

HIGH samanhappy CVE published 2026-08-31

CVE-2026-79746

A vulnerability in MCPHub, a unified hub for managing multiple MCP servers/APIs, allows unauthorized access to servers within a group when using a bearer key with accessType: 'servers' or 'custom'. This issue, patched in version 1.0.31, grants access to the entire group if any single server in that group appears in the key's allowedServers list, even if the key is scoped to a specific server.

HIGH samanhappy CVE published 2026-08-31

CVE-2026-79745

A vulnerability in MCPHub, a unified hub for managing multiple MCP servers/APIs, allows unauthorized users to create, overwrite, and shadow global prompt templates and resources. This issue, patched in version 1.0.32, results in an unauthorized integrity violation. The vulnerability stems from a lack of role checking in the built-in prompt and resource controllers, enabling non-admin users to tamper with [truncated]

HIGH samanhappy CVE published 2026-08-31

CVE-2026-79744

CVE-2026-79744 is a high-severity vulnerability in MCPHub, a unified hub for managing multiple MCP servers/APIs. The vulnerability exists in the PUT /api/system-config endpoint, which lacks proper authorization checks, allowing unauthorized system configuration changes. This issue was patched in version 1.0.29. Defenders managing MCPHub instances should assess exposure to this vulnerability and prioritize [truncated]

MEDIUM samanhappy CVE published 2026-08-31

CVE-2026-79743

CVE-2026-79743 is a vulnerability in MCPHub, a unified hub for managing multiple MCP servers/APIs. Prior to version 0.12.13, an attacker can craft a malicious MCPB file to extract files to an arbitrary location on the file system and potentially delete arbitrary directories. This vulnerability allows for potential security breaches and data tampering. Defenders should assess exposure and prioritize patchi [truncated]