{"id":"CVE-2026-58168","aliases":["GHSA-jg88-rvpc-qvxj"],"title":"DeepTutor missing MCP tool authorization allows non-admin users to invoke unrestricted tools","summary":"DeepTutor missing MCP tool authorization allows non-admin users to invoke unrestricted tools","severity":"high","cvss":8.8,"cwe":["CWE-862"],"vendor":"deeptutor","product":"deeptutor","ecosystem":"pip","affected":["deeptutor < 1.4.10"],"patched":["deeptutor 1.4.10"],"published":"2026-06-30","updated":"2026-10-02","sourceUpdated":"2026-10-02T18:27:30Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-jg88-rvpc-qvxj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58168"},{"url":"https://github.com/HKUDS/DeepTutor/pull/579"},{"url":"https://github.com/HKUDS/DeepTutor/commit/90046374b3dcd4f8a866d2d64a64440bc08eb2ef"},{"url":"https://github.com/HKUDS/DeepTutor/releases/tag/v1.4.10"},{"url":"https://www.vulncheck.com/advisories/deeptutor-insecure-default-grants-unrestricted-mcp-tool-access-to-non-admin-users"},{"url":"https://github.com/advisories/GHSA-jg88-rvpc-qvxj"}],"tags":["ghsa","pip"],"epss":0.00597,"epssPercentile":0.4669,"ingestedAt":"2026-10-02T22:33:09.858Z","slug":"CVE-2026-58168","body":"## Overview\n\nDeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources.\n\n## Affected packages\n\n- `deeptutor < 1.4.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `deeptutor 1.4.10`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}