Loading market data...
← Back to CVE feed

CVE-2026-101064

HIGH CVSS 7.6 View on NVD ↗

Description

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Published: Sep 27, 2026 21:17 UTC Modified: Sep 28, 2026 13:17 UTC