VDB
Sign up
HIGH7.5

PYSEC-2026-2000

Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification

Quick fix

PYSEC-2026-2000 — utcp: upgrade to the fixed version with the command below.

pip install --upgrade 'utcp>=1.1.0'

Details

The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can later change the manual to exploit the client.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/utcp
Introduced in: 0Fixed in: 1.1.0
Fixpip install --upgrade 'utcp>=1.1.0'

References