VYPR

Python Utcp

by Universal Tool Calling Protocol

Source repositories

CVEs (10)

  • CVE-2026-45369HigMay 14, 2026
    risk 0.54cvss 8.3epss 0.00

    python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without any sanitization or escaping. These commands are then executed…

  • CVE-2026-101060HigSep 27, 2026
    risk 0.53cvss 8.2epss —

    python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302…

  • CVE-2026-45370HigMay 14, 2026
    risk 0.50cvss 7.7epss 0.00

    python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with CVE-2026-45369, an attacker can exfiltrate all process-level secrets in a single…

  • CVE-2026-101059HigSep 27, 2026
    risk 0.46cvss 7.1epss —

    utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated…

  • CVE-2026-101058MedSep 27, 2026
    risk 0.45cvss 6.9epss —

    python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally…

  • CVE-2025-14542HigDec 13, 2025
    risk 0.42cvss 7.5epss 0.00

    The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can…

  • CVE-2026-12210MedJun 15, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-websocket. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is…

  • CVE-2026-101061MedSep 27, 2026
    risk 0.31cvss 4.7epss —

    utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while…

  • CVE-2026-44661MedMay 14, 2026
    risk 0.31cvss 4.7epss 0.00

    python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL…

  • CVE-2026-101057LowSep 27, 2026
    risk 0.20cvss 3.1epss —

    utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without the ensure_secure_url validation that the HTTP-family plugins apply, so the HTTPS/WSS-or-loopback rule is not…