Description
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.
Published: 2026-09-27
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Confidentiality breach via SSRF
Action: Immediate Patch
AI Analysis

Impact

A server‑side request forgery flaw in the MCP registration flow allows an attacker with Power User or higher privileges to specify any target URL. The system then performs the request and returns error messages that can leak internal credentials or sensitive configuration data, enabling disclosure of secrets or internal services. The weakness is a direct pathway to compromise confidentiality of the underlying network and data.

Affected Systems

The vulnerability affects the obot-platform : obot software before version 0.23.0. No additional products or downstream dependencies are listed.

Risk and Exploitability

The CVSS score of 8.3 places the flaw in the high‑severity range, indicating significant risk when exploited. EPSS data is not available, so the precise probability of exploitation cannot be quantified, but the fact that no KEV listing exists suggests the vulnerability has not yet been publicly exploited at scale. The likely attack vector involves privileged users leveraging the logical interface of MCP registration to trigger arbitrary outbound requests; thus, users with elevated roles are an immediate target as malicious actors can reach internal services or cloud metadata endpoints and obtain credentials in the response.

Generated by OpenCVE AI on September 27, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to obot v0.23.0 or newer, which removes the SSRF capability.
  • Re‑evaluate role assignments and restrict Power User or higher privileges to necessary users, limiting their ability to access the MCP registration endpoint.
  • Deploy network segmentation or firewall rules to block outbound requests from the obot service to internal IP ranges and cloud metadata endpoints, and enable logging to detect anomalous outbound traffic.

Generated by OpenCVE AI on September 27, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.
Title Obot before v0.23.0 Server-Side Request Forgery via MCP
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T20:49:55.344Z

Reserved: 2026-09-27T16:38:56.428Z

Link: CVE-2026-101064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T21:17:01.893

Modified: 2026-09-27T21:17:01.893

Link: CVE-2026-101064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T22:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)