Obot: Server-Side Request Forgery via remote MCP server URL
Obot versions up to 0.22.1 have a server-side request forgery (SSRF) vulnerability where privileged users can register remote MCP server URLs that Obot fetches without proper destination validation. This allows requests to internal network services and the cloud metadata endpoint (169.254.169.254), potentially exposing cloud IAM credentials. The vulnerability is fixed in version 0.23.0 by enforcing outbound egress restrictions on loopback, link-local, private IP ranges, and IPv6 ULA addresses.
AI Analysis
Technical Summary
In Obot versions <= 0.22.1 with authentication enabled, the URL of a remote MCP server is attacker-controlled at registration and fetched server-side without validation of the destination IP. The system does not block requests to loopback, link-local, RFC1918 private IP ranges, or the cloud metadata service at 169.254.169.254. Privileged users (Power User or higher) can exploit this to coerce Obot into making requests to internal services and the cloud metadata endpoint, with responses reflected in error messages, enabling non-blind SSRF. The vulnerability is addressed in v0.23.0 by implementing a single outbound egress chokepoint that rejects disallowed IP ranges uniformly.
Potential Impact
An attacker with Power User, Power User Plus, or Admin privileges can exploit this SSRF to access internal-only services and the cloud instance metadata service. Accessing the cloud metadata service can disclose the host's cloud IAM credentials, allowing an attacker to pivot into the cloud environment. The vulnerability has a CVSS v3.1 score of 7.6 (High) with high confidentiality impact and low integrity impact.
Mitigation Recommendations
Upgrade to Obot version 0.23.0 or later, which implements a uniform outbound egress filter rejecting loopback, link-local (including 169.254.169.254), RFC1918 private IP ranges, and IPv6 ULA addresses at dial time. This fix prevents SSRF to internal and cloud metadata endpoints. No additional mitigations are required if upgraded.
Obot: Server-Side Request Forgery via remote MCP server URL
Description
Obot versions up to 0.22.1 have a server-side request forgery (SSRF) vulnerability where privileged users can register remote MCP server URLs that Obot fetches without proper destination validation. This allows requests to internal network services and the cloud metadata endpoint (169.254.169.254), potentially exposing cloud IAM credentials. The vulnerability is fixed in version 0.23.0 by enforcing outbound egress restrictions on loopback, link-local, private IP ranges, and IPv6 ULA addresses.
CVSS v3.1
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Obot versions <= 0.22.1 with authentication enabled, the URL of a remote MCP server is attacker-controlled at registration and fetched server-side without validation of the destination IP. The system does not block requests to loopback, link-local, RFC1918 private IP ranges, or the cloud metadata service at 169.254.169.254. Privileged users (Power User or higher) can exploit this to coerce Obot into making requests to internal services and the cloud metadata endpoint, with responses reflected in error messages, enabling non-blind SSRF. The vulnerability is addressed in v0.23.0 by implementing a single outbound egress chokepoint that rejects disallowed IP ranges uniformly.
Potential Impact
An attacker with Power User, Power User Plus, or Admin privileges can exploit this SSRF to access internal-only services and the cloud instance metadata service. Accessing the cloud metadata service can disclose the host's cloud IAM credentials, allowing an attacker to pivot into the cloud environment. The vulnerability has a CVSS v3.1 score of 7.6 (High) with high confidentiality impact and low integrity impact.
Mitigation Recommendations
Upgrade to Obot version 0.23.0 or later, which implements a uniform outbound egress filter rejecting loopback, link-local (including 169.254.169.254), RFC1918 private IP ranges, and IPv6 ULA addresses at dial time. This fix prevents SSRF to internal and cloud metadata endpoints. No additional mitigations are required if upgraded.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jgh3-fggc-mcpm
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade53055bf5e2cf5edc2ed
Added to database: 09/19/2026, 01:28:16 UTC
Last enriched: 09/19/2026, 01:56:29 UTC
Last updated: 09/19/2026, 03:00:52 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.