github.com/obot-platform/obot
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/obot-platform/obotpage 1 of 1
- CVE-2026-101062HIGHCVSS 8.8EG 8.8✓ Fixed in 0.23.02026-09-27
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register.…
- CVE-2026-101063MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.23.02026-09-27
Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, reposit…
- CVE-2026-101064HIGHCVSS 7.6EG 7.6✓ Fixed in 0.23.02026-09-27
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can…
- CVE-2026-101084CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.21.12026-09-27
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks t…
Check whether github.com/obot-platform/obot is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/obot-platform/obot CVEs against the assets you own.
Book a Demo →