CVE-2025-11287
BaseFortify
Publication date: 2025-10-05
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mcphubx | mcphub | to 0.9.10 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the samanhappy MCPHub software up to version 0.9.10, specifically in the handleSseConnection function of the src/services/sseService.ts file. It allows an attacker to manipulate the function leading to improper authentication. The attack can be launched remotely, and an exploit is publicly available.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to bypass proper authentication remotely, potentially gaining unauthorized access to the system or data. This can lead to compromised confidentiality, integrity, and availability of the affected system.