obot-platform obot
6 known vulnerabilities in obot-platform obot, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103758 CVSS 8.6 high Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the…
- CVE-2026-101084 CVSS 9.3 critical obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect…
- CVE-2026-101065 CVSS 9.3 critical Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented…
- CVE-2026-101064 CVSS 8.3 high Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to…
- CVE-2026-101063 CVSS 6.9 medium Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is…
- CVE-2026-101062 CVSS 8.7 high Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client…