NVD HIGH: CVE-2026-101062 — Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENAB...
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own dom
CVE-2026-101062