Executive brief
python-utcp is a library that allows applications to discover and invoke tools through UTCP manuals. When a client fetches a tool manual from a remote server, the library failed to validate that tool URLs don't point to the victim's own loopback address (127.0.0.1), allowing an attacker to redirect tool calls to local services. An attacker who can serve a malicious manual can cause the client to access internal services and leak their responses back to the attacker.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the http, sse, and streamable_http protocol handlers. When discovering UTCP manuals from non-loopback origins, the library failed to reject tool URLs pointing to loopback addresses, despite having such checks in the OpenAPI converter path. Native manuals bypass the OpenAPI converter's loopback validation. Exploitation requires the attacker to serve a malicious UTCP manual that the victim registers, and further requires an unauthenticated loopback service on the victim host that returns useful data.
Affected products
- Universal Tool Calling Protocol python-utcp before 1.1.12
Timeline
- 2026-09-05: disclosed: GitHub security advisory published
- 2026-09-27: patched: Version 1.1.12 released with fix