CVE-2026-105138
HIGH
7,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.
522
Insufficiently Protected Credentials
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, ICS/OT
https://github.com/obot-platform/obot
https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859…
https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859…
https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e93…
https://github.com/obot-platform/obot/releases/tag/v0.26.2
https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq
https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-expos…