CVE-2026-101057

CVE-2026-101057 published: utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without the ensure_secure_url validation that the HTTP-family plugins apply, so the HTTPS/WSS-or-lo...

View full NVD advisory → ← Back to CVE watch