Junglewise Threat Intelligence

CVE-2026-58168: HKUDS DeepTutor authorization bypass in MCP tool access

CVE-2026-58168 · Severity: high · CVSS 8.8 · Published 2026-06-30

Vendors: HKUDS.

Executive brief

DeepTutor, an AI-powered tutoring and agent platform, contains a security flaw where low-privileged users can access powerful system tools they should not be able to reach. This allows an attacker or a malicious AI prompt to bypass restrictions and interact directly with the server's filesystem, web browser, or command shell. Such access could lead to the theft of sensitive data, unauthorized system changes, or full compromise of the server hosting the application.

Technical details

An authorization bypass exists in DeepTutor's multi-user tool access logic within `deeptutor/multi_user/tool_access.py`. The `allowed_mcp_tools` function incorrectly returned `None` (interpreted as unrestricted access) instead of a denied result when the `mcp_tools` field was omitted from a user's grant configuration. A remote attacker with low-privileged credentials, or a malicious actor using prompt injection, can enumerate and invoke any configured MCP tool. This includes tools for filesystem access, shell execution, and browser interaction, potentially leading to full remote code execution or sensitive resource exposure. The vulnerability is resolved in version 1.4.10 by implementing a 'fail-closed' policy for non-admin users.

Affected products

  • HKUDS DeepTutor < 1.4.10

Timeline

  • 2026-06-21: patched: Version 1.4.10 released and fix PR merged.
  • 2026-06-30: disclosed: CVE-2026-58168 published.

References