Executive brief
utcp-gql and utcp-websocket are Python libraries that enable applications to connect to remote services via GraphQL and WebSocket protocols. Both libraries fail to properly validate URLs before making outbound connections, allowing attackers who control tool URLs to force connections to internal systems, cloud metadata services, and other sensitive endpoints. When exploited, attackers receive API keys and OAuth tokens configured in the application, leading to credential compromise and unauthorized access to internal infrastructure.
Technical details
The GraphQL plugin uses a vulnerable startswith() prefix check that accepts URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite security requirements stated in its documentation. Both plugins attach configured API keys, Basic auth, and OAuth2 Bearer tokens to outbound connection headers. An attacker supplying malicious tool URLs in call templates can bypass validation and force the client to connect to arbitrary internal services and cloud metadata endpoints, exfiltrating credentials to attacker-controlled hosts.
Affected products
- universal-tool-calling-protocol utcp-gql before 1.1.1
- universal-tool-calling-protocol utcp-websocket before 1.1.1
Timeline
- 2026-09-27: disclosed: Security advisory published
- 2026-09-27: patched: Versions 1.1.1 released with fixes