Sceawere

Vulnerability Detail

CVE-2026-101058UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF via UTCP Loopback Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.9
Creation Date
14h ago
Vendor
universal-tool-calling-protocol
Product
python-utcp
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.9",
  "pubDate": "2026-09-27T18:16:31.973Z",
  "pubdate": "2026-09-27T18:16:31.973Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the python-utcp (utcp-http) package, specifically in versions prior to 1.1.12.\nThe vulnerability arises from an improper validation mechanism within the 'ensure_secure_url' function, which fails to verify if tool URLs defined in a UTCP manual point to the local loopback interface (127.0.0.1) when the manual is retrieved from a remote, non-loopback source.\nBy serving a malicious UTCP manual to a client, an attacker can coerce the victim's agent to perform unauthorized HTTP, SSE, or streamable_http requests against local services bound to the loopback interface.\nThe primary impact is the unauthorized exfiltration of sensitive information or interaction with internal services that rely on local network trust.\nExploitation requires the attacker to successfully trick a victim into registering a malicious UTCP manual from a remote location and necessitates the presence of an unauthenticated service on the target's loopback interface capable of providing useful data.",
  "technicalDetails": "The root cause of this SSRF vulnerability is a flaw in the validation logic responsible for ensuring the security of URLs declared in a hand-written UTCP manual. While the system intended to permit loopback HTTP for legitimate local development, the implementation of 'ensure_secure_url' and the OpenAPI converter failed to sufficiently distinguish between trusted local sources and untrusted remote sources.\nWhen a UTCP manual is fetched from a non-loopback origin, the client fails to enforce a restriction against loopback addresses in the tool URLs defined within that manual. Consequently, the agent interprets these malicious URLs as authorized requests.\nThe attack flow begins when an attacker hosts a malicious UTCP manual on a remote server. The victim client retrieves this manual, which specifies target tool URLs pointing to local loopback services (e.g., http://127.0.0.1:[port]/endpoint).\nBecause the 'ensure_secure_url' function incorrectly permits these loopback addresses, the agent executes the requests. The 'http', 'sse', and 'streamable_http' protocols are explicitly identified as vulnerable avenues for this interaction.\nThe response bodies generated by these local services are then returned to the caller, effectively allowing the attacker to bypass network boundary protections and access internal, unauthenticated resources residing on the host machine.\nReach is restricted to the local loopback interface, meaning the attacker cannot directly pivot to other network segments; however, this is sufficient to compromise services that assume internal safety based on their binding to 127.0.0.1. The vulnerability is remediated in version 1.1.12, which implements a check against the final post-redirect discovery URL. If the discovery origin is determined to be non-loopback, the client now rejects any manual declaring loopback tool URLs."
}
CVE-2026-101058: SSRF via UTCP Loopback Bypass (MEDIUM Severity, CVSS: 6.9) | Sceawere