Sceawere

Vulnerability Detail

CVE-2026-101061UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF in utcp-gql and utcp-websocket

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
14h ago
Vendor
universal-tool-calling-protocol
Product
python-utcp
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-27T18:16:32.407Z",
  "pubdate": "2026-09-27T18:16:32.407Z",
  "executiveSummary": "The utcp-gql and utcp-websocket packages contain critical Server-Side Request Forgery (SSRF) vulnerabilities stemming from insufficient implementation of previous security fixes (CVE-2026-44661). These flaws affect versions prior to 1.1.1. The vulnerability allows remote attackers to force the underlying server to initiate unauthorized outbound requests to internal resources, including cloud metadata services and restricted local network endpoints. By providing malicious tool URLs within call templates, an attacker can manipulate the application to perform server-side requests, leading to the exfiltration of sensitive information, such as API keys and OAuth tokens, to external, attacker-controlled infrastructure. The exploitation of these vulnerabilities does not require advanced access if the application exposes mechanisms to process user-supplied URLs, representing a significant risk to the integrity and confidentiality of internal infrastructure and associated service credentials.",
  "technicalDetails": "The vulnerability arises from two distinct failures in input validation and protocol security within the utcp-gql and utcp-websocket plugins. In utcp-gql, the root cause is an incomplete fix for CVE-2026-44661 involving a flawed prefix-based URL validation mechanism. The implementation allows for DNS-based bypass techniques; for instance, an attacker can supply a crafted URL such as 'http://127.0.0.1.attacker.example'. Due to the deficient logic, the filter fails to recognize the internal IP address encoded within the hostname structure, permitting requests to loop back to the local host or internal network segments.\nIn the case of utcp-websocket, the vulnerability is characterized by a complete absence of URL validation. Despite documentation explicitly stating that security requirements necessitate strict URL filtering, the implementation performs no verification on the destination address. This allows an attacker to define any arbitrary URI as a target for the WebSocket connection.\nThe attack flow proceeds as follows: 1) An attacker identifies a feature within the application that accepts user-supplied tool URLs or call templates. 2) The attacker submits a payload designed to target sensitive internal services, such as internal REST APIs, databases, or cloud provider metadata services (e.g., 169.254.169.254). 3) The vulnerable component, failing to validate or sanitize the input, initiates a network request using the server's identity. 4) The server processes the connection to the internal target. 5) Sensitive data retrieved from these internal services, such as temporary security credentials, configuration files, or API keys, is subsequently transmitted to an external host controlled by the attacker via the payload's configured call template.\nThese vulnerabilities effectively turn the vulnerable server into a proxy for SSRF attacks, bypassing perimeter defenses. Because these plugins process data on behalf of the server, the requests are performed with the server's network and authentication context. Successful exploitation leads to unauthorized access to internal systems, lateral movement within the network, and the potential for complete compromise of authentication tokens and environment-specific secrets, facilitating further exfiltration or privilege escalation."
}
CVE-2026-101061: SSRF in utcp-gql and utcp-websocket (MEDIUM Severity, CVSS: 4.7) | Sceawere