Sceawere

Vulnerability Detail

CVE-2026-101064UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Obot SSRF via MCP Registration

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
11h ago
Vendor
obot-platform
Product
obot
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-09-27T21:17:01.893Z",
  "pubdate": "2026-09-27T21:17:01.893Z",
  "executiveSummary": "Obot versions prior to v0.23.0 are susceptible to a server-side request forgery (SSRF) vulnerability originating from the remote Model Context Protocol (MCP) server registration functionality.\nThe vulnerability arises from a failure to validate or sanitize user-supplied URLs during the registration process for external MCP services.\nAn attacker possessing 'Power User' privileges or higher can weaponize this flaw to force the application to perform arbitrary HTTP requests.\nThis capability allows for the traversal of internal network boundaries, enabling interaction with internal services and cloud metadata APIs (e.g., AWS/GCP/Azure instance metadata services).\nThe primary impact includes the exfiltration of sensitive information, such as cloud credentials, API keys, and internal configuration details, which are leaked through verbose application error messages.\nGiven the ability to pivot into internal infrastructure, this vulnerability represents a significant risk to the confidentiality and integrity of the hosting environment.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper validation of the target URL parameter within the Obot remote MCP server registration module. The application accepts a user-provided URL intended to point to an MCP-compatible server but fails to implement a robust allowlist or blocklist mechanism to restrict the destination of the resulting outbound request.\nThe exploitation flow begins when an authenticated user with elevated privileges (Power User or higher) interacts with the MCP registration endpoint. By supplying a crafted URL—such as 'http://169.254.169.254/latest/meta-data/iam/security-credentials/'—the attacker triggers a server-side request originating from the Obot backend.\nBecause the system lacks server-side request validation, the backend process initiates a connection to the specified internal or metadata address. The application subsequently processes the server's response. If the connection results in an error or an unexpected response format, the Obot backend reflects the content of that response within the application's error messages returned to the user.\nThis reflection mechanism essentially serves as an oracle, allowing an attacker to bypass internal network segmentation and interact with services reachable from the Obot server's network namespace. In cloud-native deployments, this permits the exfiltration of short-lived identity tokens used by the host instance, potentially granting the attacker escalated permissions within the cloud environment.\nThe vulnerability is specifically constrained to the registration process for remote MCP servers, meaning the target component is the input processing logic governing third-party server integration. The issue remains present in all versions of Obot prior to v0.23.0, and successful exploitation is strictly dependent on the attacker already possessing the requisite 'Power User' or administrative credentials."
}
CVE-2026-101064: Obot SSRF via MCP Registration (HIGH Severity, CVSS: 7.6) | Sceawere