PT-2026-99570 · Pypi · @Utcp/Http
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
python-utcp (pip package utcp-http) versions prior to 1.1.12
Description
The software fails to verify if tool URLs in a hand-written UTCP manual point to the agent's own loopback interface when the manual is retrieved from a remote, non-loopback origin. This occurs because the
ensure secure url function permits loopback HTTP for local development, and native manuals bypassed the loopback check used by the OpenAPI converter. An attacker providing a malicious UTCP manual can trigger server-side request forgery (SSRF), causing the client to send requests to services bound to 127.0.0.1 on the victim host and return the response bodies to the attacker. This issue affects the http, sse, and streamable http protocols. Exploitation requires a loopback service that responds to unauthenticated requests.Recommendations
Update python-utcp (pip package utcp-http) to version 1.1.12.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Utcp/Http