在 utcp-http 1.1.4 版本之前,该库未对来自远程 OpenAPI 规范的 OAuth2 tokenUrl 字段进行验证,这会导致攻击者将凭据提交重定向到任意端点。当受害者注册一个由攻击者控制的 OpenAPI 规范并调用一个生成的 OAuth2 保护工具时,该库会将受害者的 client_id 和 client_secret 以 POST 方式发送到攻击者指定的 token 端点,而不对 URL 进行任何验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| universal-tool-calling-protocol | python-utcp | 0 ~ 1.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101060 | 8.2 HIGH | python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects |
| CVE-2026-101058 | 6.9 MEDIUM | python-utcp before 1.1.12 SSRF via Remote HTTP Manual |
| CVE-2026-101061 | 4.7 MEDIUM | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass |
| CVE-2026-101057 | 3.1 LOW | utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL |
No comments yet