Vulnerability  ·  2026-10-03

Obot MCP gateway: /mcp-connect-composite/ route bypasses UI-fallback deny list → Basic users use restricted MCP servers (CVE-2026-103758)

VulnerabilityMedium impactGlobalCVE-2026-103758
NVD published CVE-2026-103758 on 2026-10-01 (GitHub advisory GHSA-6fwv-3h4c-37j9): the fix for the earlier /mcp-connect/{id} bypass (GHSA-vw82) omitted the sibling composite route, leaving /mcp-connect-composite/{mcp_id} unguarded. Any authenticated user with a composite MCP ID can reach MCP servers gated by Access Control Rules, calling tools regardless of registry membership. CVSS 8.1, CWE-863/CWE-1289.
The MCP gateway is the authorization boundary for an agent platform; this is a residual authorization-bypass that nullifies the admin's group restrictions and lets low-privilege users invoke MCP tools (reads and actions) on protected integrations — an agent-framework authorization-bypass with a real blast radius.
The checkUI deny list covers the /mcp-connect/ prefix but not the composite route /mcp-connect-composite/{mcp_id}, which reaches the same mcpGateway.Proxy handler. checkUI returns true, so Authorize short-circuits and Basic-role users proxy requests to MCP servers that were meant to be group-restricted.
Obot 0.21.1 - 0.24.1
Upgrade to a patched Obot release implementing the advisory fix (and ideally widening the deny-list prefix to /mcp-connect and making checkUI fail closed).
Obot GitHub advisory GHSA-6fwv-3h4c-37j9NVD CVE-2026-103758
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →