PT-2026-99710 · Obot · Obot
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Obot versions prior to 0.23.0
Description
Obot contains a server-side request forgery (SSRF) issue during remote MCP server registration. Privileged users with Power User, Power User Plus, or Admin roles can specify arbitrary URLs in the
RemoteRuntimeConfig.URL variable without destination validation. The system fails to block requests to loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (169.254.169.254). Consequently, an attacker can coerce the server into making requests to internal services and the cloud instance metadata service, reading the responses via error messages to disclose sensitive information, such as cloud IAM credentials.Recommendations
Upgrade to version 0.23.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Obot