Vulnerability  ·  2026-10-02

Obot /mcp-connect-composite route omitted from authz deny list lets basic-role users invoke restricted MCP tools

VulnerabilityHigh impactGlobalCVE-2026-103758
An authorization-bypass in Obot's composite MCP connection path: the deny-list used for UI access control fails to cover /mcp-connect-composite/, so authenticated low-privilege (basic-role) users can reach MCP servers protected by Access Control Rules and invoke their tools via the composite MCP gateway.
Obot's whole value is scoped, mediated access to MCP servers; an authz gap at the composite-connect route erodes the platform's least-privilege promise, letting an unprivileged account drive restricted MCP tools (data access, external actions) through the agent broker.
The checkUI deny list that enforces route-level authorization omits the /mcp-connect-composite/ route; a basic-role authenticated user with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules (CVSS 8.1, incorrect authorization / CWE-863). This is distinct from the earlier /mcp-connect bypass (already patched in 0.21.1); it is a new composite-route variant.
Obot 0.21.1 through 0.24.1
Apply the Obot security advisory GHSA-6fwv-3h4c-37j9 update (fixed after 0.24.1)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →