---
id: CVE-2026-101064
title: >-
  Obot before v0.23.0 contains a server-side request forgery vulnerability in
  remote MCP server registration that allows privileged users to specify
  arbitrary URLs without destination validation
summary: >-
  Obot before v0.23.0 contains a server-side request forgery vulnerability in
  remote MCP server registration that allows privileged users to specify
  arbitrary URLs without destination validation. Attackers with Power User or
  higher roles c…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: obot-platform
product: obot
affected:
  - obot < 0.23.0
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T21:17:01.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101064'
references:
  - url: >-
      https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/obot-before-0.23.0-server-side-request-forgery-via-mcp
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T20:58:01.540Z'
---

## Overview

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
