Server-Side Request Forgery Vulnerability in Obot by GitHub
CVE-2026-101064
8.3HIGH
What is CVE-2026-101064?
Obot versions prior to v0.23.0 are vulnerable to a server-side request forgery (SSRF) issue, specifically during the registration of remote MCP servers. This allows authenticated users with Power User roles or above to submit arbitrary URLs, bypassing destination validation. As a result, attackers can manipulate Obot into making unintended requests to internal services and cloud metadata endpoints. This may lead to the leaking of sensitive information such as credentials through error message responses.
Affected Version(s)
obot 0 < 0.23.0
obot 0.23.0
