CVE-2026-101061: utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
utcp-gql and utcp-websocketto a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Deployments using utcp-gql or utcp-websocket versions earlier than 1.1.1 should be prioritized, especially where tool URLs can be supplied through call templates and the service can reach internal networks or cloud metadata endpoints.
What does an attacker need to exploit this issue?
An attacker needs to supply a malicious tool URL in a call template and induce the affected plugin to use it. No authentication privilege is required, but exploitation requires user interaction and has high attack complexity.
How do the affected plugins differ in their exposure?
In utcp-gql, URL validation relies on a vulnerable prefix check that can be bypassed with hosts such as 127.0.0.1.attacker.example. In utcp-websocket, no URL validation is performed despite the documented security requirement.
What sensitive data could be exposed through a successful exploit?
The affected plugins can be made to connect to attacker-controlled hosts and send configured API keys and OAuth tokens. They can also be used to reach internal services and cloud metadata endpoints.
How can teams determine whether they are affected?
Identify installations of utcp-gql or utcp-websocket earlier than version 1.1.1, then review whether call templates permit attacker-influenced tool URLs. Instances with configured API keys or OAuth tokens and network access to internal or cloud metadata services have greater impact.