High
github
·
GHSA-xwmw-prc4-v3cr
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Published Sep 18, 2026
CVSS 8.8
Summary
In affected versions, an unauthenticated attacker could register an OAuth client with an arbitrary external redirect URI, and the authorization flow would auto-complete without a consent screen. If a logged-in victim visited a crafted authorization URL, an authorization code was delivered to the attacker's redirect URI and exchanged for an access token. That token was minted with the victim's full set of groups, so it could be used as a bearer token against the Obot API endpoints the victim had access to — rather than being scoped to just the requested MCP server.
Am I affected?
You are affected if you run Obot `
Affected AI Products
mcp server