在 Obot 0.26.0 至 0.26.2 版本之间(不含 0.26.2)存在一个授权绕过漏洞,允许匹配任何 vMCP 配置文件的已认证用户访问未授权组件的提示和资源。由于这些配置文件的授权控制仅施加于工具(tools)上,攻击者可以通过 vMCP 所有者的共享组件连接,访问提示、资源以及资源模板。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| obot-platform | obot | 0.26.0 ~ 0.26.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105138 | 6.5 MEDIUM | Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API |
| CVE-2026-105140 | 4.2 MEDIUM | Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group M |
No comments yet