GHSA-r8j5-8747-88cm
MODERATECVE-2026-45366The @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HTTPS / loopback allowlist, but callTool() reuses the resolved toolCallTemplate.url directly without revalidating, and the OpenApiConverter blindly trusts whatever servers[0]
- Affected
- >=0, <1.1.2, <= 1.1.1
- Fixed in
- 1.1.2
- Weakness
- CWE-918
- Published
- 2026-05-14
- Source
- osv