Impact
MCPHub had a horizontal IDOR in its tool-execution API that allowed any authenticated non‑admin user to invoke arbitrary tools on MCP servers owned by other users. The vulnerability permitted the attacker to read files on the host (such as "/etc/passwd" and user secrets) and perform server‑side request forgery against internal endpoints. This flaw is an example of CWE‑639: Unauthorized Access to Privileged Data.
Affected Systems
The affected product is MCPHub from samanhappy. Versions prior to 1.0.30 allowed the exploit; the issue was patched in release 1.0.30 and later versions. All other versions remain vulnerable until updated.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a valid non‑admin user account and does not rely on privileged access or administrative credentials. Because the attacker can invoke any available tool, the risk of further compromise is significant once an account is compromised.
OpenCVE Enrichment