Impact
MCPHub versions prior to 1.0.32 embed an OAuth 2.0 authorization server that, by default, does not require client authentication and allows optional PKCE enforcement. An attacker who obtains an authorization code can redeem it for an access token without providing a client secret or a PKCE verifier, thereby bypassing the intended authentication checks and gaining authenticated access to a victim’s account.
Affected Systems
The vulnerability affects the MCPHub product from the vendor samanhappy, specifically versions released before 1.0.32.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity flaw that threatens confidentiality, integrity, and availability by allowing attackers to impersonate users. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Attackers can exploit this by intercepting an authorization code over an insecure channel and exchanging it for an access token without the required client credentials or PKCE verifier, creating an unauthorized access path to victim accounts.
OpenCVE Enrichment