Impact
A bearer key limited to specific servers or configured for 'custom' unexpectedly allows a client to access every server in any group that contains at least one permitted server. The flaw in the server‑matching logic bypasses fine‑grained authorization, effectively granting full read and control over the entire group for a key that was intended to be highly restricted. This weakness, classified as CWE-863, could let an attacker read, modify, or delete data across all affected servers, compromising confidentiality, integrity, and availability for the entire group.
Affected Systems
The bug affects MCPHub versions prior to 1.0.31, distributed by the vendor samanhappy. Users running MCPHub 1.0.30 or earlier are vulnerable. The patched release 1.0.31, available as of the referenced GitHub release, removes the flawed logic.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. Because the flaw is triggered simply by supplying a bearer key with any overlap in allowed servers, an attacker can exploit it remotely from any network location that can reach the MCPHub endpoint. The EPSS score is not available, but the lack of a known exploit in public domains and its inclusion in a recent security advisory suggest high exploitation potential. The vulnerability is not listed in the CISA KEV catalog yet. Attackers do not need elevated privileges or privilege escalation; having a valid bearer key suffices to gain full group access.
OpenCVE Enrichment