Obot 在 v0.23.0 之前(受影响的版本为 ≤ v0.22.1),当配置了 时,会暴露 OAuth 动态客户端注册功能,且该注册无需身份验证,同时对客户端可注册的回调 URI(redirect URIs)没有任何限制。 由于授权流程在用户已登录的情况下会自动完成,无需经过同意屏幕(consent screen),攻击者可以注册一个指向其自有域名的客户端,并诱导已登录的受害者访问一个精心构造的授权 URL。随后,攻击者将在其控制的回调 URI 上接收到授权码(authorization code),并可将该授
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| obot-platform | obot | 0 ~ 0.23.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101065 | 9.8 CRITICAL | Obot Quickstart Docker Deployment Unauthenticated Admin Access |
| CVE-2026-101084 | 9.6 CRITICAL | obot before v0.21.1 Authorization Bypass via /mcp-connect |
| CVE-2026-101064 | 7.6 HIGH | Obot before v0.23.0 Server-Side Request Forgery via MCP |
| CVE-2026-101063 | 5.3 MEDIUM | Obot before v0.23.0 Authentication Bypass via Registry API |
No comments yet