VYPR

DeepTutor

by DeepTutor

CVEs (1)

  • CVE-2026-58168Jun 30, 2026
    risk 0.00cvss epss 0.00

    DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in…