CVE-2026-94047

Summary

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Upgrading to version 1.0.33 is sufficient to resolve this issue. The identifier of the patch is 18a4467bc4ec6390b1f841d8a468a37e9922f837. It is advisable to upgrade the affected component.

Affected Software

VendorProductVersion RangeStatus
samanhappyMCPHub1.0.0affected
samanhappyMCPHub1.0.1affected
samanhappyMCPHub1.0.2affected
samanhappyMCPHub1.0.3affected
samanhappyMCPHub1.0.4affected
samanhappyMCPHub1.0.5affected
samanhappyMCPHub1.0.6affected
samanhappyMCPHub1.0.7affected
samanhappyMCPHub1.0.8affected
samanhappyMCPHub1.0.9affected
samanhappyMCPHub1.0.10affected
samanhappyMCPHub1.0.11affected
samanhappyMCPHub1.0.12affected
samanhappyMCPHub1.0.13affected
samanhappyMCPHub1.0.14affected
samanhappyMCPHub1.0.15affected
samanhappyMCPHub1.0.16affected
samanhappyMCPHub1.0.17affected
samanhappyMCPHub1.0.18affected
samanhappyMCPHub1.0.19affected
samanhappyMCPHub1.0.20affected
samanhappyMCPHub1.0.21affected
samanhappyMCPHub1.0.22affected
samanhappyMCPHub1.0.23affected
samanhappyMCPHub1.0.24affected
samanhappyMCPHub1.0.25affected
samanhappyMCPHub1.0.26affected
samanhappyMCPHub1.0.27affected
samanhappyMCPHub1.0.28affected
samanhappyMCPHub1.0.29affected
samanhappyMCPHub1.0.30affected
samanhappyMCPHub1.0.31affected
samanhappyMCPHub1.0.32affected
samanhappyMCPHub1.0.33unaffected

Weaknesses

  • CWE-269: Improper Privilege Management
  • CWE-266: Incorrect Privilege Assignment

References