Vulnerability  ·  2026-09-28

Obot OAuth dynamic client registration bypass: token theft with full user group set via crafted authorization URL

VulnerabilityHigh impactGlobalCVE-2026-101062
NVD published on 2026-09-27 (VulnCheck): unauthenticated OAuth dynamic client registration with unrestricted redirect URIs, combined with an auto-completing authorization flow, lets an attacker steal an access token carrying the victim's full group set, usable against any Obot API endpoint (CVSS 8.8 v3.1).
An agent/MCP platform's OAuth trust boundary is the linchpin of agent identity. One link click hands the attacker a token that can read or modify the victim's agent configurations, workflows, and MCP connections — a direct path to hijacking an AI agent deployment via its authentication layer.
OAuth dynamic client registration is unauthenticated and unrestricted on redirect URIs; the already-logged-in user's authorization flow auto-completes with no consent screen. An attacker registers a client pointing at their domain and sends a single crafted authorization URL to a victim; the resulting token carries the victim's full group set and (because only issuer, not audience, was validated) is accepted as a bearer token against any Obot API endpoint the victim can access.
obot-platform/obot <= v0.22.1; fixed in v0.23.0
Upgrade to obot v0.23.0 (adds a consent screen, scopes MCP OAuth tokens to the involved MCP, enforces audience validation). Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr
NVD CVE-2026-101062GitHub Security Advisory GHSA-xwmw-prc4-v3cr
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →