Obot 0.12.0 至 0.26.2 版本存在凭据保护不足的安全漏洞,该漏洞允许已认证用户读取由管理员或高级用户在 MCP(Model Context Protocol)目录条目中设置的静态密钥。通过访问控制规则被授予某条目访问权限的普通用户,可发起对 的请求,从而获取明文格式的 API 密钥或令牌,并利用这些凭据滥用后端服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| obot-platform | obot | 0.12.0 ~ 0.26.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105139 | 4.3 MEDIUM | Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources |
| CVE-2026-105140 | 4.2 MEDIUM | Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group M |
No comments yet