In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @samanhappy/mcphub to version 0.12.17 or higher.
@samanhappy/mcphub is an A hub server for mcp servers
Affected versions of this package are vulnerable to User Impersonation via the sseUserContextMiddleware process. An attacker can gain unauthorized access to user sessions and perform actions as any user, including administrators, by supplying arbitrary usernames in the URL path without authentication. This is only exploitable if bearer authentication is disabled or not configured.