{"schema_version":1,"title":"Samanhappy vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Samanhappy: 1 in the last 7 days and 10 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94047, was published on 20 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/samanhappy","json_url":"https://junglewise.ai/threats/vendors/samanhappy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/samanhappy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":5,"all_time":15,"critical":2,"exploited":0,"last_7_days":1,"last_30_days":10,"last_90_days":10,"last_365_days":15},"latest":[{"cve":"CVE-2026-94047","cvss":6.3,"epss":0.0043,"slug":"cve-2026-94047-a-security-vulnerability-has-been-detected-in-samanhappy-mcphub","title":"samanhappy MCPHub privilege management in template import","severity":"medium","exploited":false,"published_at":"2026-09-20T20:16:53.79+00:00","url":"https://junglewise.ai/threats/cve-2026-94047-a-security-vulnerability-has-been-detected-in-samanhappy-mcphub"},{"cve":"CVE-2026-90474","cvss":6.8,"epss":0.0055,"slug":"cve-2026-90474-mcphub-oauth-2-0-authentication-bypass-in-authorization-server","title":"MCPHub OAuth 2.0 authentication bypass in authorization server","severity":"medium","exploited":false,"published_at":"2026-09-12T11:16:34.483+00:00","url":"https://junglewise.ai/threats/cve-2026-90474-mcphub-oauth-2-0-authentication-bypass-in-authorization-server"},{"cve":"CVE-2026-79750","cvss":7.7,"epss":0.0043,"slug":"cve-2026-79750-mcphub-horizontal-privilege-escalation-in-tool-execution-api","title":"MCPHub horizontal privilege escalation in tool execution API","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.627+00:00","url":"https://junglewise.ai/threats/cve-2026-79750-mcphub-horizontal-privilege-escalation-in-tool-execution-api"},{"cve":"CVE-2026-79749","epss":0.0045,"slug":"cve-2026-79749-mcphub-ssrf-guard-bypass-in-ipv6-transition-address-handling","title":"MCPHub SSRF guard bypass in IPv6 transition address handling","severity":"info","exploited":false,"published_at":"2026-08-31T18:17:20.483+00:00","url":"https://junglewise.ai/threats/cve-2026-79749-mcphub-ssrf-guard-bypass-in-ipv6-transition-address-handling"},{"cve":"CVE-2026-79748","cvss":9.9,"epss":0.0064,"slug":"cve-2026-79748-mcphub-privilege-escalation-in-server-configuration-endpoints","title":"MCPHub privilege escalation in server configuration endpoints","severity":"critical","exploited":false,"published_at":"2026-08-31T18:17:20.34+00:00","url":"https://junglewise.ai/threats/cve-2026-79748-mcphub-privilege-escalation-in-server-configuration-endpoints"},{"cve":"CVE-2026-79747","cvss":7.1,"epss":0.003,"slug":"cve-2026-79747-mcphub-ssrf-in-server-registration","title":"MCPHub SSRF in server registration","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.2+00:00","url":"https://junglewise.ai/threats/cve-2026-79747-mcphub-ssrf-in-server-registration"},{"cve":"CVE-2026-79746","cvss":8.1,"epss":0.0043,"slug":"cve-2026-79746-mcphub-bearer-key-privilege-escalation-on-group-routes","title":"MCPHub bearer key privilege escalation on group routes","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.057+00:00","url":"https://junglewise.ai/threats/cve-2026-79746-mcphub-bearer-key-privilege-escalation-on-group-routes"},{"cve":"CVE-2026-79745","cvss":7.1,"epss":0.0044,"slug":"cve-2026-79745-mcphub-unauthorized-modification-of-global-prompt-and-resource","title":"MCPHub unauthorized modification of global prompt and resource templates","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:19.91+00:00","url":"https://junglewise.ai/threats/cve-2026-79745-mcphub-unauthorized-modification-of-global-prompt-and-resource"},{"cve":"CVE-2026-79744","cvss":8.8,"epss":0.0056,"slug":"cve-2026-79744-mcphub-missing-authorization-on-put-api-system-config","title":"MCPHub missing authorization on PUT /api/system-config","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:19.763+00:00","url":"https://junglewise.ai/threats/cve-2026-79744-mcphub-missing-authorization-on-put-api-system-config"},{"cve":"CVE-2026-79743","cvss":4,"epss":0.0054,"slug":"cve-2026-79743-mcphub-path-traversal-via-malicious-mcpb-manifest-name","title":"MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible","severity":"medium","exploited":false,"published_at":"2026-08-31T18:17:19.61+00:00","url":"https://junglewise.ai/threats/cve-2026-79743-mcphub-path-traversal-via-malicious-mcpb-manifest-name"},{"cvss":3.1,"slug":"mcphub-sse-endpoint-authentication-bypass-enabling-user-impersonation-78450d1b","title":"mcphub SSE endpoint authentication bypass enabling user impersonation","severity":"low","exploited":false,"published_at":"2026-05-14T20:44:22+00:00","url":"https://junglewise.ai/threats/mcphub-sse-endpoint-authentication-bypass-enabling-user-impersonation-78450d1b"},{"cvss":9.1,"slug":"samanhappy-mcphub-authentication-bypass-via-user-impersonation-in-sse-40c22314","title":"samanhappy MCPHub authentication bypass via user impersonation in SSE endpoint","severity":"critical","exploited":false,"published_at":"2026-05-14T20:44:22+00:00","url":"https://junglewise.ai/threats/samanhappy-mcphub-authentication-bypass-via-user-impersonation-in-sse-40c22314"},{"cve":"CVE-2025-13822","cvss":4,"epss":0.0035,"slug":"cve-2025-13822-samanhappy-mcphub-authentication-bypass-in-api-endpoints","title":"samanhappy MCPHub authentication bypass in API endpoints","severity":"medium","exploited":false,"published_at":"2026-04-14T12:31:28+00:00","url":"https://junglewise.ai/threats/cve-2025-13822-samanhappy-mcphub-authentication-bypass-in-api-endpoints"},{"cve":"CVE-2025-11287","cvss":4,"epss":0.0056,"slug":"cve-2025-11287-mcphub-improper-authorization-in-handlesseconnection","title":"MCPHub improper authorization in handleSseConnection","severity":"medium","exploited":false,"published_at":"2025-10-05T09:30:19+00:00","url":"https://junglewise.ai/threats/cve-2025-11287-mcphub-improper-authorization-in-handlesseconnection"},{"cve":"CVE-2025-11285","cvss":4,"epss":0.0779,"slug":"cve-2025-11285-mcphub-servercontroller-command-injection","title":"MCPHub ServerController command injection","severity":"medium","exploited":false,"published_at":"2025-10-05T06:30:14+00:00","url":"https://junglewise.ai/threats/cve-2025-11285-mcphub-servercontroller-command-injection"}],"vendor":{"hub":true,"name":"Samanhappy","slug":"samanhappy","homepage":"https://github.com/samanhappy","description":"samanhappy is an open-source developer on GitHub.","url":"https://junglewise.ai/threats/vendors/samanhappy"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-79748","cvss":9.9,"epss":0.0064,"slug":"cve-2026-79748-mcphub-privilege-escalation-in-server-configuration-endpoints","title":"MCPHub privilege escalation in server configuration endpoints","severity":"critical","exploited":false,"published_at":"2026-08-31T18:17:20.34+00:00","url":"https://junglewise.ai/threats/cve-2026-79748-mcphub-privilege-escalation-in-server-configuration-endpoints"},{"cvss":9.1,"slug":"samanhappy-mcphub-authentication-bypass-via-user-impersonation-in-sse-40c22314","title":"samanhappy MCPHub authentication bypass via user impersonation in SSE endpoint","severity":"critical","exploited":false,"published_at":"2026-05-14T20:44:22+00:00","url":"https://junglewise.ai/threats/samanhappy-mcphub-authentication-bypass-via-user-impersonation-in-sse-40c22314"},{"cve":"CVE-2026-79744","cvss":8.8,"epss":0.0056,"slug":"cve-2026-79744-mcphub-missing-authorization-on-put-api-system-config","title":"MCPHub missing authorization on PUT /api/system-config","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:19.763+00:00","url":"https://junglewise.ai/threats/cve-2026-79744-mcphub-missing-authorization-on-put-api-system-config"},{"cve":"CVE-2026-79746","cvss":8.1,"epss":0.0043,"slug":"cve-2026-79746-mcphub-bearer-key-privilege-escalation-on-group-routes","title":"MCPHub bearer key privilege escalation on group routes","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.057+00:00","url":"https://junglewise.ai/threats/cve-2026-79746-mcphub-bearer-key-privilege-escalation-on-group-routes"},{"cve":"CVE-2026-79750","cvss":7.7,"epss":0.0043,"slug":"cve-2026-79750-mcphub-horizontal-privilege-escalation-in-tool-execution-api","title":"MCPHub horizontal privilege escalation in tool execution API","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.627+00:00","url":"https://junglewise.ai/threats/cve-2026-79750-mcphub-horizontal-privilege-escalation-in-tool-execution-api"},{"cve":"CVE-2026-79745","cvss":7.1,"epss":0.0044,"slug":"cve-2026-79745-mcphub-unauthorized-modification-of-global-prompt-and-resource","title":"MCPHub unauthorized modification of global prompt and resource templates","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:19.91+00:00","url":"https://junglewise.ai/threats/cve-2026-79745-mcphub-unauthorized-modification-of-global-prompt-and-resource"},{"cve":"CVE-2026-79747","cvss":7.1,"epss":0.003,"slug":"cve-2026-79747-mcphub-ssrf-in-server-registration","title":"MCPHub SSRF in server registration","severity":"high","exploited":false,"published_at":"2026-08-31T18:17:20.2+00:00","url":"https://junglewise.ai/threats/cve-2026-79747-mcphub-ssrf-in-server-registration"},{"cve":"CVE-2026-90474","cvss":6.8,"epss":0.0055,"slug":"cve-2026-90474-mcphub-oauth-2-0-authentication-bypass-in-authorization-server","title":"MCPHub OAuth 2.0 authentication bypass in authorization server","severity":"medium","exploited":false,"published_at":"2026-09-12T11:16:34.483+00:00","url":"https://junglewise.ai/threats/cve-2026-90474-mcphub-oauth-2-0-authentication-bypass-in-authorization-server"},{"cve":"CVE-2026-94047","cvss":6.3,"epss":0.0043,"slug":"cve-2026-94047-a-security-vulnerability-has-been-detected-in-samanhappy-mcphub","title":"samanhappy MCPHub privilege management in template import","severity":"medium","exploited":false,"published_at":"2026-09-20T20:16:53.79+00:00","url":"https://junglewise.ai/threats/cve-2026-94047-a-security-vulnerability-has-been-detected-in-samanhappy-mcphub"},{"cve":"CVE-2025-11285","cvss":4,"epss":0.0779,"slug":"cve-2025-11285-mcphub-servercontroller-command-injection","title":"MCPHub ServerController command injection","severity":"medium","exploited":false,"published_at":"2025-10-05T06:30:14+00:00","url":"https://junglewise.ai/threats/cve-2025-11285-mcphub-servercontroller-command-injection"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Samanhappy Mcphub","slug":"mcphub","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/mcphub"}]}