What happened
An authorization-bypass in Obot's composite MCP connection path: the deny-list used for UI access control fails to cover /mcp-connect-composite/, so authenticated low-privilege (basic-role) users can reach MCP servers protected by Access Control Rules and invoke their tools via the composite MCP gateway.
Why it matters
Obot's whole value is scoped, mediated access to MCP servers; an authz gap at the composite-connect route erodes the platform's least-privilege promise, letting an unprivileged account drive restricted MCP tools (data access, external actions) through the agent broker.
Attack vector
The checkUI deny list that enforces route-level authorization omits the /mcp-connect-composite/ route; a basic-role authenticated user with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules (CVSS 8.1, incorrect authorization / CWE-863). This is distinct from the earlier /mcp-connect bypass (already patched in 0.21.1); it is a new composite-route variant.
Affected systems
Obot 0.21.1 through 0.24.1
Mitigation
Apply the Obot security advisory GHSA-6fwv-3h4c-37j9 update (fixed after 0.24.1)