Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials. | |
| Title | Obot before v0.23.0 Server-Side Request Forgery via MCP | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T20:49:55.344Z
Reserved: 2026-09-27T16:38:56.428Z
Link: CVE-2026-101064
No data.
Status : Received
Published: 2026-09-27T21:17:01.893
Modified: 2026-09-27T21:17:01.893
Link: CVE-2026-101064
No data.
OpenCVE Enrichment
Updated: 2026-09-27T22:30:17Z