Obot 是一个开源的 AI Agent / MCP(Model Context Protocol)平台。在包含提交 d7e6970 在内的所有版本中,README 文档中记录的 Docker 快速启动命令会将容器绑定到 0.0.0.0:8080,并且默认禁用身份验证。当身份验证被禁用时,所有请求都会被映射到一个名为“nobody”的合成用户,该用户拥有 Owner(所有者)和 Admin(管理员)角色。因此,任何能够访问该暴露端口的未认证用户都能获得对 Obot API 和 UI 的完全管理员访问权限,包括注册和
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| obot-platform | obot | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101084 | 9.6 CRITICAL | obot before v0.21.1 Authorization Bypass via /mcp-connect |
| CVE-2026-101062 | 8.8 HIGH | Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration |
| CVE-2026-101064 | 7.6 HIGH | Obot before v0.23.0 Server-Side Request Forgery via MCP |
| CVE-2026-101063 | 5.3 MEDIUM | Obot before v0.23.0 Authentication Bypass via Registry API |
No comments yet