Impact
The vulnerability is a CWE-863 Authorization Bypass that permits authenticated users to access the /mcp-connect-composite/ route in Obot. The grant of this route allows users to proxy requests to MCP servers through the mcpGateway.Proxy endpoint, enabling them to invoke tools that are normally protected by Access Control Rules. This could lead to the execution of privileged commands or manipulation of data on the MCP servers, effectively granting attackers privileges than intended for their user role.
Affected Systems
Vendors and products impacted are obot-platform’s obot running versions 0.21.1 through 0.24.1. No specific sub‑version granularity is listed beyond this range, but any installation of those releases should be treated as vulnerable.
Risk and Exploitability
The CVSS score of 8.6 signals a high severity and indicates that the vulnerability is exploitable by a legitimate user account that is able to authenticate to Obot. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly known exploits at the time of this report. The likely attack path involves an attacker logging into the application with a user that has basic role privileges and then sending a crafted request to the /mcp-connect-composite/ endpoint, which bypasses the authorization checks.
OpenCVE Enrichment