Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/obot-platform/obot
  4. ›
  5. GHSA-jgh3-fggc-mcpm

GHSA-jgh3-fggc-mcpm: Obot: Server-Side Request Forgery via remote MCP server URL

September 18, 2026

In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (169.254.169.254), so a use with the Power User, Power User Plus, or Admin role can coerce Obot into making requests to internal services and to the cloud instance metadata service, and read the responses.

References

  • github.com/advisories/GHSA-jgh3-fggc-mcpm
  • github.com/obot-platform/obot/releases/tag/v0.23.0
  • github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm

Code Behaviors & Features

Detect and mitigate GHSA-jgh3-fggc-mcpm with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.23.0

Fixed versions

  • 0.23.0

Solution

Upgrade to version 0.23.0 or above.

Impact 7.6 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-1188: Initialization of a Resource with an Insecure Default
  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/obot-platform/obot/GHSA-jgh3-fggc-mcpm.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:20:05 +0000.