Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101061— utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass

Quick assessment

Affected
universal-tool-calling-protocol python-utcp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

utcp-gql 1.1.1 之前版本以及 utcp-websocket 1.1.1 之前版本存在服务器端请求伪造(SSRF)漏洞,这是因为对 CVE-2026-44661 修复措施的应用不完整。其中,GraphQL 插件使用了一种存在缺陷的前缀检查机制,允许攻击者绕过 URL 限制,例如构造类似 http://127.0.0.1.attacker.example 的 URL;而 WebSocket 插件则完全未对 URL 进行任何验证,尽管其文档中明确提出了安全要求。攻击者可以通过在调用模板中提供恶意的工具 UR

CVSS 4.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101061

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass
Source: CVE Program / CVE List V5
Vulnerability Description
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
universal-tool-calling-protocol python-utcp 0 ~ 1.1.1 -
universal-tool-calling-protocol python-utcp 0 ~ 1.1.1 -

II. Public POCs for CVE-2026-101061

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101061

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101061 (1)

Other References for CVE-2026-101061 (1)

Same Patch Batch · universal-tool-calling-protocol · 2026-09-27 · 5 CVEs total

CVE-2026-101060 8.2 HIGH python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
CVE-2026-101059 7.1 HIGH utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
CVE-2026-101058 6.9 MEDIUM python-utcp before 1.1.12 SSRF via Remote HTTP Manual
CVE-2026-101057 3.1 LOW utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-101061

No comments yet


Leave a comment