PT-2026-99709 · Obot · Obot
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Obot versions prior to 0.23.0
Description
When registry authentication is enabled via the
OBOT SERVER ENABLE REGISTRY AUTH variable, the software fails to enforce authentication on MCP Registry endpoints under the /v0.1/* path. This occurs because the authorizer uses a fixed set of protected prefixes and default-allows others; since the /v0.1 prefix was missing from this set, anonymous requests were authorized before reaching the authentication challenge. Unauthenticated attackers can send GET requests to the /v0.1/servers endpoint to read registry metadata, including server names, descriptions, repository URLs, and connect URLs. This issue does not expose credential values, and unauthenticated users cannot connect to the servers as the connection process remains protected.Recommendations
Upgrade to version 0.23.0 or later.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Obot