CVE-2026-101064: Obot before v0.23.0 Server-Side Request Forgery via MCP
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Exploitation requires a user with the Power User role or a higher-privileged role. The attack can be performed remotely and does not require user interaction.
What systems or data could be reached through the vulnerable server?
A privileged attacker can register a remote MCP server using arbitrary URLs, causing Obot to request internal services or cloud metadata endpoints. Responses may be exposed in error messages, potentially disclosing sensitive credentials.
What versions need remediation?
Obot versions before 0.23.0 are affected. Updating to version 0.23.0 or later addresses the affected version range described here.
How can I determine whether exploitation may have occurred?
Review remote MCP server registrations created by Power Users or higher roles for URLs targeting internal address space or cloud metadata services. Also inspect related error messages for responses that may contain credentials or other sensitive data.