Vulnerability  ·  2026-09-28

Obot SSRF in remote MCP server registration reaches internal services / cloud metadata

VulnerabilityMedium impactGlobalCVE-2026-101064
NVD published on 2026-09-27 (VulnCheck): Obot before v0.23.0 contains an SSRF in remote MCP server registration with no destination validation, exploitable by Power User or higher roles to read internal/cloud-metadata responses in error messages.
MCP registration is the mechanism by which an agent platform reaches backend systems; an SSRF here turns a privileged-but-not-admin agent user into a scanner for internal infrastructure and IAM cloud-metadata credential harvesting in AI deployments.
A Power User or higher registers a remote MCP server with an arbitrary URL; Obot fetches that destination without validation (SSRF), and the response is disclosed in error output — enabling reads of internal services and cloud metadata endpoints that can expose credentials (CVSS 7.6 v3.1).
obot-platform/obot < v0.23.0
Upgrade to obot v0.23.0. Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm
NVD CVE-2026-101064GitHub Security Advisory GHSA-jgh3-fggc-mcpm
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →