utcp-mcp(python-utcp 的 MCP 插件)在 1.1.2 及更早版本中,调用模板中 mcpServers 配置所指定的 HTTP 和 WebSocket MCP 服务器 URL 时,未应用 HTTP 系列插件所实施的 ensure_secure_url 安全验证,因此不会强制实施“仅允许 HTTPS/WSS 或本地回环地址”的策略。如果调用模板中配置了纯 HTTP 且非本地回环的 MCP 服务器 URL,系统会按配置直接发起连接,从而导致 MCP 握手过程暴露于网络中间人攻击之下,并允许向内部主机
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| universal-tool-calling-protocol | python-utcp | 0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101060 | 8.2 HIGH | python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects |
| CVE-2026-101059 | 7.1 HIGH | utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass |
| CVE-2026-101058 | 6.9 MEDIUM | python-utcp before 1.1.12 SSRF via Remote HTTP Manual |
| CVE-2026-101061 | 4.7 MEDIUM | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass |
No comments yet