Skip to content
archivevulnerability · 18 Sep 2026 · 17:59 UTC

GHSA-jgh3-fggc-mcpm: Obot: Server-Side Request Forgery via remote MCP server URL

HIGHHigh-risk vulnerability — CVSS 7.6

last 60 dispatches · spectrum

## Summary In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (`169.254.169.254`), so a use with the Power User, Power User Plus, or Admin role can coerce Obot into making requests to internal services and to the cloud instance metadata service, and read the responses. ## Am I affected? …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected