Lyrie
AI Threats
1 sources verified·1 min read
By Lyrie Threat Intelligence·5/13/2026

Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server

_AI Threats — being enriched by Lyrie Threat Intelligence._

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]GitHub Advisory