CVE-2026-101059 HIGH

CVE-2026-101059: utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass

Vendor Universal-Tool-Calling-Protocol
Product python-utcp
Weakness CWE-918 · SSRF
Published September 27, 2026
Last update September 27, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's client_id and client_secret to the attacker-supplied token endpoint without URL validation.

Key dates

02Disclosure timeline

September 27, 2026 CVE published

Related vulnerabilities

04Related CVE