Impact
The vulnerability is a server‑side request forgery that allows an attacker to instruct the affected component to issue HTTP requests to arbitrary destinations. This flaw can lead to unintended data exposure, unauthorized access to internal resources, or interaction with external services at the behest of the attacker. The weakness is an improper validation of outgoing URLs, classified as CWE‑918.
Affected Systems
Universal‑Tool‑Calling‑Protocol python‑utcp version 1.1.0 is affected. The flaw resides in the utcp‑gql/utcp‑websocket module, and no further version details are available.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The attack can be launched remotely and a public exploit exists. Because the vendor did not provide a response, the risk remains moderate but potentially elevated if the service is exposed to untrusted networks.
OpenCVE Enrichment