Executive brief
The utcp-gql and utcp-websocket plugins, which handle tool invocations over GraphQL and WebSocket respectively, fail to properly validate connection URLs before opening outbound connections. An attacker who can influence tool configuration can craft URLs with hostnames like `127.0.0.1.attacker.example` that bypass simplistic prefix checks (or perform no validation at all), forcing the client to make requests to internal services, cloud metadata endpoints, or attacker-controlled servers while automatically forwarding authentication credentials such as API keys or OAuth tokens.
Technical details
Server-Side Request Forgery (SSRF / CWE-918) affecting two UTCP communication protocol plugins. The GraphQL plugin (`utcp-gql`) validates URLs using a flawed string prefix check: `url.startswith("http://localhost")` or `url.startswith("http://127.0.0.1")`. This allows bypass URLs such as `http://127.0.0.1.attacker.example/graphql` and `http://localhost.evil.com/graphql` to pass validation; if an attacker controls DNS for `attacker.example`, the hostname resolves to an arbitrary IP (including internal ranges like 192.168.x.x or metadata endpoints like 169.254.169.254). The WebSocket plugin (`utcp-websocket`) performs no hostname validation at all despite docstring claims of enforcing "WSS or localhost only"; any URL in a WebSocketCallTemplate connects without checks. Both plugins attach configured authentication headers (API key, Basic Auth, OAuth Bearer tokens) to all outbound connections, leaking credentials when the SSRF forces a connection to an attacker-controlled host. Attack requires the ability to influence tool manuals registered by a UTCP client. Fix: version 1.1.1 replaces prefix checks with proper hostname-based validation using `ensure_secure_url()` and introduces `ensure_secure_ws_url()` for WebSocket schemes; both also disable HTTP redirects (set `allow_redirects=False`) to prevent post-validation redirect SSRF.
Affected products
- universal-tool-calling-protocol utcp-gql <= 1.1.0
- universal-tool-calling-protocol utcp-websocket <= 1.1.0
Timeline
- 2026-06-14: disclosed: GitHub Advisory published (earlier disclosure date on record)
- 2026-08-25: advisory: Advisory updated with patch information
- 2026-08-25: patched: utcp-gql 1.1.1 and utcp-websocket 1.1.1 released with fixes