Impact
DeepTutor prior to version 1.4.10 lacks proper authorization checks for MCP tool access. The system’s allowed_mcp_tools function returns None when a user’s grant omits mcp_tools, effectively granting permission instead of denying it. This flaw enables low‑privilege users or prompt‑injected content within a user session to enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, thereby accessing sensitive deployment resources without authorization. The flaw is a CWE-862 Authorization Bypass vulnerability.
Affected Systems
All installations of DeepTutor from the initial release up to, but not including, version 1.4.10 are affected. The product is distributed by HKUDS and any deployment relying on earlier releases is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating high severity. Exploitation does not require special network exposure; it can be achieved by any low‑privilege user with access to a user session. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, but the inherent authorization bypass presents a serious risk of unauthorized data and system access if left unmitigated.
OpenCVE Enrichment