CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability in Obot versions 0.21.1 to 0.24.1 allows authenticated users to access MCP servers by exploiting an oversight in the checkUI deny list, which fails to restrict the /mcp-connect-composite/ route. This flaw enables basic-role users with a composite MCP ID to proxy requests and execute tools on MCP servers that should be protected by Access Control Rules. Organizations using affected versions should prioritize remediation to prevent unauthorized access and potential exploitation of sensitive resources.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.