What happened
NVD published on 2026-09-27 (VulnCheck): unauthenticated OAuth dynamic client registration with unrestricted redirect URIs, combined with an auto-completing authorization flow, lets an attacker steal an access token carrying the victim's full group set, usable against any Obot API endpoint (CVSS 8.8 v3.1).
Why it matters
An agent/MCP platform's OAuth trust boundary is the linchpin of agent identity. One link click hands the attacker a token that can read or modify the victim's agent configurations, workflows, and MCP connections — a direct path to hijacking an AI agent deployment via its authentication layer.
Attack vector
OAuth dynamic client registration is unauthenticated and unrestricted on redirect URIs; the already-logged-in user's authorization flow auto-completes with no consent screen. An attacker registers a client pointing at their domain and sends a single crafted authorization URL to a victim; the resulting token carries the victim's full group set and (because only issuer, not audience, was validated) is accepted as a bearer token against any Obot API endpoint the victim can access.
Affected systems
obot-platform/obot <= v0.22.1; fixed in v0.23.0
Mitigation
Upgrade to obot v0.23.0 (adds a consent screen, scopes MCP OAuth tokens to the involved MCP, enforces audience validation). Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr