PT-2026-99710 · Obot · Obot

·

CVE-2026-101064

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Obot versions prior to 0.23.0
Description Obot contains a server-side request forgery (SSRF) issue during remote MCP server registration. Privileged users with Power User, Power User Plus, or Admin roles can specify arbitrary URLs in the RemoteRuntimeConfig.URL variable without destination validation. The system fails to block requests to loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (169.254.169.254). Consequently, an attacker can coerce the server into making requests to internal services and the cloud instance metadata service, reading the responses via error messages to disclose sensitive information, such as cloud IAM credentials.
Recommendations Upgrade to version 0.23.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101064
GHSA-JGH3-FGGC-MCPM
GO-2026-6522

Affected Products

Obot