High
github
·
GHSA-jgh3-fggc-mcpm
Obot: Server-Side Request Forgery via remote MCP server URL
Published Sep 18, 2026
CVSS 7.6
Summary
In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (169.254.169.254), so a use with the Power User, Power User Plus, or Admin role can coerce Obot into making requests to internal services and to the cloud instance metadata service, and read the responses.
Am I affected?
You are affected if you run Obot `
Affected AI Products
mcp server