PT-2026-99708 · Obot · Obot
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Obot versions prior to 0.23.0
Description
When running with
OBOT SERVER ENABLE AUTHENTICATION=true, the software exposes OAuth dynamic client registration without authentication and without restrictions on redirect URIs. This allows an unauthenticated attacker to register a client pointing to an external domain. Because the authorization flow auto-completes for logged-in users without a consent screen, an attacker can induce a victim to visit a crafted authorization URL to receive an authorization code at the attacker-controlled redirect URI, which is then exchanged for an access token and refresh token.The token minted by the MCP OAuth flow includes the victim's full group set in the JWT (JSON Web Token), a format for securely transmitting information. Since the system validates the issuer but not the audience, the token is accepted as a bearer token against any Obot API endpoint the victim can access, rather than being scoped to the requested MCP server. This enables the attacker to read or modify the victim's resources until the token is revoked.
Recommendations
Upgrade to version 0.23.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Obot