Impact
Obot versions prior to 0.23.0 do not require authentication when registry authentication is enabled. As a result, an attacker who sends a simple unauthenticated GET request to the /v0.1/servers endpoint can read registry metadata such as server names, descriptions, repository URLs, and connect URLs. The vulnerability allows unauthorized information disclosure that could aid in reconnaissance and further attack planning.
Affected Systems
The affected software is obot-platform’s obot product. All builds released before version 0.23.0 are vulnerable. The vulnerability resides in the MCP Registry API exposed under the /v0.1/* path.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA KEV. Attackers can exploit it remotely by issuing unauthenticated HTTP GET requests to the exposed API, which is reachable over the network. Because the authentication step is simply omitted, the patch or configuration change is straightforward once discovered.
OpenCVE Enrichment