在 utcp-http(pip 包)1.1.12 版本之前,存在一个安全漏洞。该漏洞未验证由用户手动编写的 UTCP 手册中声明的工具 URL 是否指向代理自身的回环接口(loopback interface),特别是在这些手册是从远程(非回环)源被发现的情况下。 由于 故意允许用于本地开发的回环 HTTP 请求,而本机手册绕过了 OpenAPI 转换器所执行的回环检查,攻击者可以提供一份 UTCP 手册供受害者注册,从而诱导客户端向仅绑定到 127.0.0.1 的目标主机上的服务发起请求,并将响应体返回给调用方(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| universal-tool-calling-protocol | python-utcp | 0 ~ 1.1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101060 | 8.2 HIGH | python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects |
| CVE-2026-101059 | 7.1 HIGH | utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass |
| CVE-2026-101061 | 4.7 MEDIUM | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass |
| CVE-2026-101057 | 3.1 LOW | utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL |
No comments yet