{"id":"GHSA-jg88-rvpc-qvxj","summary":"DeepTutor missing MCP tool authorization allows non-admin users to invoke unrestricted tools","details":"DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources.","aliases":["CVE-2026-58168"],"modified":"2026-10-02T18:45:04.941618464Z","published":"2026-06-30T18:31:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-02T18:27:29Z","nvd_published_at":"2026-06-30T17:16:23Z","cwe_ids":["CWE-862"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58168"},{"type":"WEB","url":"https://github.com/HKUDS/DeepTutor/pull/579"},{"type":"WEB","url":"https://github.com/HKUDS/DeepTutor/commit/90046374b3dcd4f8a866d2d64a64440bc08eb2ef"},{"type":"PACKAGE","url":"https://github.com/HKUDS/DeepTutor"},{"type":"WEB","url":"https://github.com/HKUDS/DeepTutor/releases/tag/v1.4.10"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/deeptutor-insecure-default-grants-unrestricted-mcp-tool-access-to-non-admin-users"}],"affected":[{"package":{"name":"deeptutor","ecosystem":"PyPI","purl":"pkg:pypi/deeptutor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.10"}]}],"versions":["1.4.0","1.4.0b0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jg88-rvpc-qvxj/GHSA-jg88-rvpc-qvxj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}