CVE-2026-79748 | samanhappy MCPHub up to 0.12.14 Server Configuration /api/servers child_process.spawn command/args privileges management
A vulnerability categorized as very critical has been discovered in samanhappy MCPHub up to 0.12.14. Affected by this issue is the function child_process.spawn of the file /api/servers of the component Server Configuration. The manipulation of the argument command/args results in improper privilege management.
This vulnerability was named CVE-2026-79748. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More