๐Ÿ” CVE Alert

CVE-2026-105138

MEDIUM 6.5

Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.

CWE CWE-522
Vendor obot-platform
Product obot
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for obot-platform obot

Be the first to know when new medium vulnerabilities affecting obot-platform obot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

obot-platform / obot
0.12.0 < 0.26.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e933def7a github.com: https://github.com/obot-platform/obot github.com: https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq github.com: https://github.com/obot-platform/obot/releases/tag/v0.26.2 github.com: https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/authz/resources.go#L27 github.com: https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/handlers/mcp.go#L206-L212 vulncheck.com: https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-exposure-via-mcp-catalog-entry-api

Credits

Scott Moore - VulnCheck