CVE Record
[ CRITICAL ]CVE-2026-101065
Obot Docker Quickstart Exposes API on All Interfaces Without Auth
The Obot AI agent platform Docker quickstart binds to 0.0.0.0:8080 by default, exposing the full API without authentication to any host that can reach the port.
- Vendor
- Obot Platform
- Product
- Obot (all versions through commit d7e6970)
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
The Obot README’s Docker quickstart command starts the container listening on 0.0.0.0:8080, binding to all network interfaces without authentication. Any host that can reach that port can access the full Obot API.
Mitigation requires binding to 127.0.0.1 or placing a reverse proxy with authentication in front of the container. The project disclosed this via GitHub Security Advisory GHSA-jj4w-pfgv-4mrm.
