Impact
obots before version v0.21.1 do not enforce the required access control on the /mcp-connect endpoint. This flaw allows any authenticated user to connect to any MCP server for which they know the server ID, bypassing normal authorization checks. An attacker who has authenticated credentials can then send MCP tool calls that use stored OAuth tokens, enabling manipulation or discovery of sensitive backend system resources. The impact is a loss of confidentiality and integrity for backend services protected by MCP.
Affected Systems
Affected products are obot from obot-platform. All releases prior to v0.21.1 are vulnerable. The vulnerability affects the obot Platform where the /mcp-connect endpoint is exposed to authenticated users.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, so the historical exploitation likelihood cannot be quantified from this data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who can request a connection to a restricted MCP by simply knowing the target server ID. An attacker can thus gain unauthorized backend access, potentially performing malicious operations using the existing OAuth credentials.
OpenCVE Enrichment