Vulnerability Description
python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with CVE-2026-45369, an attacker can exfiltrate all process-level secrets in a single tool call. This vulnerability is fixed in 1.1.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/universal-tool-calling-protocol/python-utcp/security/advisori
- https://github.com/universal-tool-calling-protocol/python-utcp/security/advisori
FAQ
What is CVE-2026-45370?
CVE-2026-45370 is a vulnerability with a CVSS score of 7.7 (HIGH). python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with C...
How severe is CVE-2026-45370?
CVE-2026-45370 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45370?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.