GPU VulnDB

Database/AI/ML frameworks & serving

Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socket

CVSS 9.3CVE-2026-101065AI/ML frameworks & servingcurated

Impact

Up to and including commit d7e6970, the Docker quickstart in Obot's README starts the container bound to 0.0.0.0:8080 with authentication disabled. With auth off every request maps to a synthetic "nobody" user holding Owner and Admin, so anyone who can reach the port gets full administrative control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The same quickstart mounts /var/run/docker.sock into the container, so the MCP runtime reached this way holds the host's Docker control surface - which on a GPU node means starting privileged containers with the accelerators attached. The fix is documentation-only: existing deployments that followed the old instructions stay vulnerable until an operator changes them.

Who can reach it

Anyone with network reach to the published port. No authentication. Affects hosts where an operator ran the documented quickstart and exposed 8080 beyond localhost.

What to do

Set OBOT_SERVER_ENABLE_AUTHENTICATION=true and restart the container before the host is reachable from any untrusted network; bind the port to localhost or behind an authenticating proxy, and drop the /var/run/docker.sock mount unless the MCP runtime genuinely needs it. There is no code fix to pull - upgrading alone will not close an already-deployed instance, so every operator who used the old quickstart must re-check their own deployment. Treat any exposed instance as compromised and audit registered MCP servers and containers on the host.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.