---
id: CVE-2025-11285
title: A vulnerability was found in samanhappy MCPHub up to 0.9.10
summary: >-
  A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this
  issue is some unknown functionality of the file
  src/controllers/serverController.ts. The manipulation of the argument
  command/args results in os command inject…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
vendor: mcphubx
product: mcphub
affected:
  - mcphub <= 0.9.10
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11285'
references:
  - url: 'https://github.com/August829/YU1/issues/6'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327043'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327043'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.659734'
    label: cna@vuldb.com
  - url: 'https://github.com/August829/YU1/issues/6'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.07794
epssPercentile: 0.94518
ingestedAt: '2026-10-09T12:53:28.682Z'
---

## Overview

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of the argument command/args results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `mcphub <= 0.9.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
