Authentication Bypass Vulnerability in Obot by Obot Platform
CVE-2026-101063
6.9MEDIUM
What is CVE-2026-101063?
Obot versions prior to 0.23.0 have a security flaw where authentication is not enforced on the MCP Registry endpoints located at /v0.1/*. This issue can be exploited by unauthenticated attackers who can send GET requests to the /v0.1/servers endpoint, allowing them to access sensitive registry metadata such as server names, descriptions, repository URLs, and connect URLs. Proper authentication mechanisms should be implemented to protect against unauthorized access and ensure the integrity of registry data.
Affected Version(s)
obot 0 < 0.23.0
obot 0.23.0
