Back

MEDIUM

typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

Published May 28, 2026

Description

typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HTTPS / loopback allowlist, but callTool() reuses the resolved toolCallTemplate.url directly without revalidating, and the OpenApiConverter blindly trusts whatever servers[0].url an attacker-hosted spec declares. An attacker who hosts a malicious OpenAPI spec on a legitimate HTTPS endpoint can declare e.g. servers: [{ url: "http://127.0.0.1:9090" }] or servers: [{ url: "http://169.254.169.254" }]; the converter then produces tools whose URL points at internal services on the agent host. This vulnerability is fixed in 1.1.2.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 28, 2026
Updated May 29, 2026
Reserved May 12, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Deferred
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-R8J5-8747-88CM