Tools AI Risk Radar ai-incident-0017
Incident record
MCPHub let any signed-in user rewrite the prompt templates served to everyone else
- Severity
- High
- Status
- Patched
- Type
- Poisoning
- Target
- MCPHub before 1.0.32
- Actor
- researcher
- CVE
- CVE-2026-79745
What happened
MCPHub had no role check on its prompt and resource management endpoints, so any authenticated non-admin user could create or overwrite the global templates served to every session. The built-in template store is consulted ahead of any connected MCP server, so a planted template reaches other users first.
This is stored prompt injection against other people’s sessions rather than against the person who plants it, which is what lifts a missing role check into this log. NVD scores it 7.1 high. Fixed in 1.0.32.
Sources
- GitHub Security Advisory GHSA-6cvf-cfch-4g7mgithub.com/samanhappy/mcphub/security/advisories/GHSA-6cvf-c…
- NVD record, CVE-2026-79745nvd.nist.gov/vuln/detail/CVE-2026-79745
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026