Executive brief
python-utcp is a protocol library used by AI agents to invoke remote tools over HTTP. The library validates that a tool's initial URL is safe but follows HTTP 302 redirects without re-validating the destination, allowing an attacker controlling a tool endpoint to redirect the client to internal services like cloud metadata endpoints or internal admin panels and exfiltrate their responses. This enables attackers to steal credentials, access internal data, or probe internal infrastructure.
Technical details
The vulnerability exists in HttpCommunicationProtocol.call_tool(), which calls ensure_secure_url() once before the HTTP request but then issues the request with aiohttp's default allow_redirects=True and performs no per-hop re-validation. An attacker controlling the tool's endpoint server can respond with a 302 redirect to an internal HTTP service (e.g., cloud metadata at 169.254.169.254, unauth internal datastores, or link-local endpoints); the library follows the redirect and returns the response body to the caller, bypassing the initial URL check. Exploitation requires either an attacker-influenced tool registration URL or a compromised legitimate tool endpoint, and an internal service reachable from the UTCP process that returns data on unauthenticated GET.
Affected products
- universal-tool-calling-protocol python-utcp before 1.1.4
Timeline
- 2026-06-14: disclosed: GitHub Security Advisory GHSA-9qhg-99ww-9mqc published
- 2026-09-27: advisory: CVE-2026-101060 published on NVD
- 2026-06-14: patched: Fix released in version 1.1.4