CVE-2026-79743 | samanhappy MCPHub up to 0.12.12 MCPB File Upload manifest.json cleanupOldMcpbServer Name path traversal

SecurityVulns

A vulnerability described as problematic has been identified in samanhappy MCPHub up to 0.12.12. Impacted is the function cleanupOldMcpbServer of the file manifest.json of the component MCPB File Upload Handler. Executing a manipulation of the argument Name can lead to path traversal.

This vulnerability is tracked as CVE-2026-79743. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More