在 python-utcp 1.1.4 之前的版本中,HttpCommunicationProtocol.call_tool 存在服务器端请求伪造(SSRF)漏洞。该函数虽然对初始工具 URL 进行了验证,但在跟随 HTTP 重定向时未重新验证目标地址。攻击者若能控制工具端点,即可返回一个 302 重定向响应,将 UTCP 客户端重定向至内部服务或云元数据端点,并获取这些内部服务的响应内容返回给调用者。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| universal-tool-calling-protocol | python-utcp | 0 ~ 1.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101059 | 7.1 HIGH | utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass |
| CVE-2026-101058 | 6.9 MEDIUM | python-utcp before 1.1.12 SSRF via Remote HTTP Manual |
| CVE-2026-101061 | 4.7 MEDIUM | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass |
| CVE-2026-101057 | 3.1 LOW | utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL |
No comments yet