How to use this reference
The maintainer identifies v0.23.0 as patched. Its release notes corroborate consent, narrower token routing and audience checks. Editorial lesson: verify issuer, intended recipient and permitted actions independently; consent alone cannot repair overbroad token acceptance.
Before reading
- OAuth client registration, consent and token audience concepts
- Delegated authorization across application and MCP boundaries
Context and limits
- Publisher prerequisites: affected versions through v0.22.1, application authentication enabled, and interaction by an already signed-in victim. No preexisting attacker account is required.
- The maintainer credits EQSTLab as reporter. No award claim is made.
- GitHub records September 18, 2026 database publication and review separately from June 22 maintainer publication. The release page displays June 17 without a year in the retrieved text; no full software-release date is inferred.
- The reviewed sources do not establish automatic revocation of previously issued tokens after upgrade; historical exposure and remediation validation remain deployment-specific.
- Conceptual defensive summary only; public disclosure grants no testing authorization.
Sources and provenance
- OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion Obot · reviewed 2026-10-03
- Obot v0.23.0 release notes Obot · reviewed 2026-10-03
- GHSA-xwmw-prc4-v3cr publication history GitHub · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.