在 samanhappy MCPHub 1.0.32 及更早版本中检测到一处安全漏洞。受影响的是 Template Import Endpoint 组件中 src/services/templateService.ts 文件里的 importTemplate 函数。对函数参数的不当操纵可导致特权管理不当(即权限提升风险)。该漏洞可被远程利用,且相关利用细节已公开披露,因此可能存在被实际利用的风险。升级到版本 1.0.33 即可解决此问题。补丁的标识符为 18a4467bc4ec6390b1f841d8a468a37
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| samanhappy | MCPHub | 1.0.0 |
affected |
1.0.1 |
affected | ||
1.0.2 |
affected | ||
1.0.3 |
affected | ||
1.0.4 |
affected | ||
1.0.5 |
affected | ||
1.0.6 |
affected | ||
1.0.7 |
affected | ||
| … +26 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| samanhappy | MCPHub | 1.0.0 |
cpe:2.3:a:samanhappy:mcphub:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet