Obot-Platform Obot vulnerabilities
6 known vulnerabilities affecting obot-platform/obot.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-101065P2CRITICALCVSS 9.8≤ *2026-09-27
CVE-2026-101065 [CRITICAL] CWE-306 CVE-2026-101065: Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner
nvd
CVE-2026-101084P2CRITICALCVSS 9.6fixed in 0.21.12026-09-27
CVE-2026-101084 [CRITICAL] CWE-639 CVE-2026-101084: obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allo
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
nvd
CVE-2026-101062P3HIGHCVSS 8.8fixed in 0.23.02026-09-27
CVE-2026-101062 [HIGH] CWE-863 CVE-2026-101062: Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=tr
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker
nvd
CVE-2026-103758P3HIGHCVSS 8.1≥ 0.21.1, ≤ 0.24.12026-10-01
CVE-2026-103758 [HIGH] CWE-863 CVE-2026-103758: Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated
Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.
nvd
CVE-2026-101064P3HIGHCVSS 7.6fixed in 0.23.02026-09-27
CVE-2026-101064 [HIGH] CWE-918 CVE-2026-101064: Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server regist
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error mess
nvd
CVE-2026-101063P4MEDIUMCVSS 5.3fixed in 0.23.02026-09-27
CVE-2026-101063 [MEDIUM] CWE-862 CVE-2026-101063: Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/*
Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and connect URLs by sending GET requests to /v0.1/servers.
nvd