Vulnerability GO-2026-6525
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 hours ago
September 28, 2026 at 04:43 PM UTC
Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot
v0.1.0-rc1 - v0.23.0-rc5
v0.1.0-rc1 - v0.23.0-rc5
Summary
Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot
Details
Obot: MCP Registry API readable without authentication in github.com/obot-platform/obot
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 hours ago
Obot: Server-Side Request Forgery via remote MCP server URL in github.com/obot-platform/obot
v0.1.0-rc1 - v0.23.0-rc5 GO-2026-6522
v0.1.0-rc1 - v0.23.0-rc5 GO-2026-6522
Unknown
3 hours ago
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion in github.com/obot-platform/obot
v0.1.0-rc1 - v0.23.0-rc5 GO-2026-6530
v0.1.0-rc1 - v0.23.0-rc5 GO-2026-6530
High Risk
10 days ago
Obot: Server-Side Request Forgery via remote MCP server URL
v0.1.0-rc1 - v0.23.0-rc5 GHSA-jgh3-fggc-mcpm
v0.1.0-rc1 - v0.23.0-rc5 GHSA-jgh3-fggc-mcpm
Medium Risk
10 days ago
Obot: MCP Registry API readable without authentication
v0.1.0-rc1 - v0.23.0-rc5 GHSA-pr6h-vr44-xq8j
v0.1.0-rc1 - v0.23.0-rc5 GHSA-pr6h-vr44-xq8j
High Risk
10 days ago
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
v0.1.0-rc1 - v0.23.0-rc5 GHSA-xwmw-prc4-v3cr
v0.1.0-rc1 - v0.23.0-rc5 GHSA-xwmw-prc4-v3cr
Impacted packages
Timeline
Published
3 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:10 PM UTC