CVE-2026-105138
Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.
| CWE | CWE-522 |
| Vendor | obot-platform |
| Product | obot |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for obot-platform obot
Be the first to know when new medium vulnerabilities affecting obot-platform obot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
obot-platform / obot
0.12.0 < 0.26.2
References
github.com: https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e933def7a github.com: https://github.com/obot-platform/obot github.com: https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq github.com: https://github.com/obot-platform/obot/releases/tag/v0.26.2 github.com: https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/authz/resources.go#L27 github.com: https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/handlers/mcp.go#L206-L212 vulncheck.com: https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-exposure-via-mcp-catalog-entry-api
Credits
Scott Moore - VulnCheck