PatchSiren

obot-platform CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL obot-platform CVE published 2026-09-27

CVE-2026-101084

CVE-2026-101084 debrief based on the supplied source corpus. The CVE record was published on 2026-09-27T21:17:02.163Z and has not been modified since then. The vulnerability affects obot versions before 0.21.1, allowing authenticated users to bypass authorization checks and connect to restricted MCP servers if they possess the server ID. This could lead to unauthorized access and manipulation of sensitive [truncated]

CRITICAL obot-platform CVE published 2026-09-27

CVE-2026-101065

CVE-2026-101065 debrief: Obot platform vulnerable to unauthenticated admin access via exposed Docker quickstart. The Obot platform's Docker quickstart command exposes the container on 0.0.0.0:8080 with authentication disabled by default, granting full administrative access to unauthenticated parties. Operators and administrators of Obot platform deployments, especially those exposing the service to untrus [truncated]

HIGH obot-platform CVE published 2026-09-27

CVE-2026-101064

CVE-2026-101064 is a server-side request forgery vulnerability in Obot before v0.23.0 that allows privileged users to specify arbitrary URLs without destination validation, potentially disclosing sensitive credentials. This vulnerability can lead to unauthorized access to internal services and cloud metadata endpoints, resulting in potential credential disclosure and other security risks. Defenders respon [truncated]

MEDIUM obot-platform CVE published 2026-09-27

CVE-2026-101063

CVE-2026-101063 is a medium-severity vulnerability in Obot versions before v0.23.0. Unauthenticated attackers can read registry metadata by sending GET requests to /v0.1/servers due to the failure to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. This issue may expose server names, descriptions, repository URLs, and connect URLs. Defenders responsib [truncated]

HIGH obot-platform CVE published 2026-09-27

CVE-2026-101062

CVE-2026-101062 is a high-severity vulnerability in Obot versions before v0.23.0. When authentication is enabled, Obot exposes OAuth dynamic client registration without authentication and without restrictions on redirect URIs. An attacker can register a client with their own domain, induce a logged-in victim to visit a crafted authorization URL, and obtain an authorization code. This code can be exchanged [truncated]