Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6jv-4hp7-3vj9

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.

EPSS

Процентиль: 12%
0.00221
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.1
nvd
2 дня назад

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.

EPSS

Процентиль: 12%
0.00221
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863