CVE Record
[ MEDIUM ]CVE-2026-101063
Obot MCP Registry Endpoints Unauthenticated When Auth Is Enabled
Obot before v0.23.0 does not enforce authentication on MCP Registry endpoints at /v0.1/* even when registry auth is configured, exposing server listings to unauthenticated callers.
- Vendor
- Obot Platform
- Product
- Obot (before v0.23.0)
- CVSS
- 5.3
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
When registry authentication is enabled in Obot, the MCP Registry API endpoints under /v0.1/* still accept unauthenticated requests. Callers can read registry metadata including the list of registered MCP servers without credentials.
Fixed in Obot v0.23.0. Disclosed via GitHub Security Advisory GHSA-pr6h-vr44-xq8j.
