Vulnerability GO-2026-5678
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 10:34 PM UTC
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server in github.com/obot-platform/obot
v0.1.0-rc1 - v0.21.1-rc3
v0.1.0-rc1 - v0.21.1-rc3
Summary
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server in github.com/obot-platform/obot
Details
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server in github.com/obot-platform/obot
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
9 days ago
Obot: Server-Side Request Forgery via remote MCP server URL
v0.1.0-rc1 - v0.23.0-rc5 GHSA-jgh3-fggc-mcpm
v0.1.0-rc1 - v0.23.0-rc5 GHSA-jgh3-fggc-mcpm
Medium Risk
9 days ago
Obot: MCP Registry API readable without authentication
v0.1.0-rc1 - v0.23.0-rc5 GHSA-pr6h-vr44-xq8j
v0.1.0-rc1 - v0.23.0-rc5 GHSA-pr6h-vr44-xq8j
High Risk
9 days ago
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
v0.1.0-rc1 - v0.23.0-rc5 GHSA-xwmw-prc4-v3cr
v0.1.0-rc1 - v0.23.0-rc5 GHSA-xwmw-prc4-v3cr
Critical
4 months ago
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server
v0.1.0-rc1 - v0.21.1-rc3 GHSA-vw82-7fv8-r6gp
v0.1.0-rc1 - v0.21.1-rc3 GHSA-vw82-7fv8-r6gp
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 10:34 PM UTC
Last Modified
3 hours ago
September 28, 2026 at 11:55 AM UTC