{"data":{"id":"b3beca91-6938-48bc-ad51-3421e9693e51","title":"CVE-2026-79745: MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate end","summary":"MCPHub is a system that manages multiple MCP servers (APIs that handle specific tasks) and routes requests to them. Before version 1.0.32, the software had a security flaw where non-admin users could create or modify global prompt templates and resources (stored instructions shared across all users) because the system didn't check user permissions. This allowed attackers to inject malicious prompts (hidden instructions in input) that would affect other users' AI sessions.","solution":"This issue has been patched in version 1.0.32.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79745","publishedAt":"2026-08-31T18:17:19.910Z","cveId":"CVE-2026-79745","cweIds":["CWE-862"],"cvssScore":"7.1","cvssSeverity":"high","severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["MCPHub"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-31T18:17:19.910Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0051"]}}