obot-platform has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.6 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.6
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- github.com/obot-platform/obot 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
obot-platform vulnerabilities
CVEs affecting obot-platform, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
GHSA-xwmw-prc4-v3crHigh· 8.8Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
▾ Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-pr6h-vr44-xq8jMedium· 5.3Obot: MCP Registry API readable without authentication
Obot: MCP Registry API readable without authentication
▾ Sunlitobot-platform · github.com/obot-platform/obotvia OSV
GHSA-jgh3-fggc-mcpmHigh· 7.6Obot: Server-Side Request Forgery via remote MCP server URL
Obot: Server-Side Request Forgery via remote MCP server URL
▾ Twilightobot-platform · github.com/obot-platform/obotvia OSV