5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/obot-platform/obot is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
GHSA-pr6h-vr44-xq8j
Obot: MCP Registry API readable without authentication
HIGH 8.8
GHSA-xwmw-prc4-v3cr
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
HIGH 7.6
GHSA-jgh3-fggc-mcpm
Obot: Server-Side Request Forgery via remote MCP server URL
CRITICAL 9.6
GO-2026-5678
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server
UNKNOWN
GHSA-vw82-7fv8-r6gp
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server in github.com/obot-platform/obot
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes