Server-Side Request Forgery Vulnerability in Obot by GitHub
CVE-2026-101064

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101064?

Obot versions prior to v0.23.0 are vulnerable to a server-side request forgery (SSRF) issue, specifically during the registration of remote MCP servers. This allows authenticated users with Power User roles or above to submit arbitrary URLs, bypassing destination validation. As a result, attackers can manipulate Obot into making unintended requests to internal services and cloud metadata endpoints. This may lead to the leaking of sensitive information such as credentials through error message responses.

Affected Version(s)

obot 0 < 0.23.0

obot 0.23.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hewei-gikaku
.