CyberRota Analysis
AI-GeneratedThe vulnerability affects the utcp-http library versions prior to 1.1.4, which improperly validates the OAuth2 tokenUrl field from remote OpenAPI specifications. This flaw enables attackers to redirect sensitive credential submissions to malicious endpoints, potentially compromising user credentials. Organizations utilizing this library for OAuth2-protected applications should prioritize patching to mitigate the risk of credential theft.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's client_id and client_secret to the attacker-supplied token endpoint without URL validation.