THREAT OPS › Threat News › [GHSA] GHSA-jgh3-fggc-mcpm (high) — Obot: Server-Side Request Forgery via remote MCP server URL
[GHSA] GHSA-jgh3-fggc-mcpm (high) — Obot: Server-Side Request Forgery via remote MCP server URL
GHSA-jgh3-fggc-mcpm Severity: high CVE: None
Obot: Server-Side Request Forgery via remote MCP server URL
## Summary
In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (`169.254.169.254`),
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-jgh3-fggc-mcpm