Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server — GHSA-VW82-7FV8-R6GP
GitHub · GitHub · GHSA-VW82-7FV8-R6GP
ID
GHSA-VW82-7FV8-R6GP
GHSA-VW82-7FV8-R6GP
Datum
Activity
Quelle
GitHub
GitHub
Vendor
GitHub
GitHub
Risiko
critical
critical
CVSS
9.6
9.6
Zusammenfassung
## Summary If you have the MCP Server ID, you can connect to the MCP server even if you don't have permissions to the server. The MCP gateway endpoint `/mcp-connect/{mcp_id}` does not enforce Access Control Rules (ACRs). Any authenticated Obot user who possesses an MCP Server ID can connect to that server through the gateway — including making tool calls — regardless of whether they are a member of any MCP Registry…
Produkt
go: github.com/obot-platform/obot
Was tun?
Allgemeine, vorsichtige Schritte (bitte prüfe die offizielle Quelle für Details):
- Priorisiere sofort Patches oder Mitigations (hohes akutes Risiko).
- Identifiziere betroffene Produktversionen und prüfe, ob du betroffen bist.
- Spiele Hersteller-Updates/Patches ein oder setze empfohlene Mitigations um.
- Lies das offizielle Advisory für betroffene Versionen und konkrete Schritte.