Vulnerabilities
Last updated 43 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Obot: MCP Registry API readable without authentication | Medium Risk 5.3 | 9 days ago | 4 hours ago |
|
|
Obot: Server-Side Request Forgery via remote MCP server URL | High Risk 7.6 | 9 days ago | 4 hours ago |
|
|
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion | High Risk 8.8 | 9 days ago | 4 hours ago |
|
|
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server | Critical 9.6 | 4 months ago | 4 hours ago |
|
|
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server in github.com/obot-platform/obot | Unknown | 3 months ago | 4 hours ago |
Page 1