Vibe Coding
CVE-2026-94047: MCPHub's template import endpoint has broken privilege management
CVE-2026-94047, published 2026-09-20, hits samanhappy MCPHub up to version 1.0.32: the `importTemplate` function in src/services/templateService.ts allows improper privilege management, remotely exploitable, with the exploit publicly disclosed. Upgrading past 1.0.32 is the fix. MCPHub is a hub that fronts multiple MCP servers, so a privilege flaw in its template import is a step up in blast radius from the single-server CVEs that dominate this beat.
Source
↳ Follow the thread