THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jgh3-fggc-mcpm (high) — Obot: Server-Side Request Forgery via remote MCP server URL

[GHSA] GHSA-jgh3-fggc-mcpm (high) — Obot: Server-Side Request Forgery via remote MCP server URL

medgithub_advisoriesPublished 2026-09-18

GHSA-jgh3-fggc-mcpm Severity: high CVE: None

Obot: Server-Side Request Forgery via remote MCP server URL

## Summary

In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (`169.254.169.254`),

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-jgh3-fggc-mcpm