What happened
NVD published on 2026-09-27 (VulnCheck): Obot before v0.23.0 contains an SSRF in remote MCP server registration with no destination validation, exploitable by Power User or higher roles to read internal/cloud-metadata responses in error messages.
Why it matters
MCP registration is the mechanism by which an agent platform reaches backend systems; an SSRF here turns a privileged-but-not-admin agent user into a scanner for internal infrastructure and IAM cloud-metadata credential harvesting in AI deployments.
Attack vector
A Power User or higher registers a remote MCP server with an arbitrary URL; Obot fetches that destination without validation (SSRF), and the response is disclosed in error output — enabling reads of internal services and cloud metadata endpoints that can expose credentials (CVSS 7.6 v3.1).
Affected systems
obot-platform/obot < v0.23.0
Mitigation
Upgrade to obot v0.23.0. Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm