CVE-2026-101064

CVE-2026-101064 published: Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to ma...

View full NVD advisory → ← Back to CVE watch