Server-Side Request Forgery in Universal Tool Calling Protocol Python UTC-P by Universal Tool Calling Protocol
CVE-2026-12210
Key Information:
- Status
- Vendor
- CVE Published:
- 15 June 2026
Badges
What is CVE-2026-12210?
A vulnerability has been identified in the universal-tool-calling-protocol python-utcp version 1.1.0, specifically within the utcp-gql/utcp-websocket component. This issue allows attackers to perform server-side request forgery (SSRF) by manipulating server requests, which can lead to unauthorized access to internal systems. The attack can be executed remotely without the need for authentication. Despite early notification to the vendor about this vulnerability, there has been no response or mitigation provided. This exploit is now publicly available, raising significant security concerns for users of this product.
Affected Version(s)
python-utcp 1.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
