---
id: CVE-2026-58168
aliases:
  - GHSA-jg88-rvpc-qvxj
title: >-
  DeepTutor missing MCP tool authorization allows non-admin users to invoke
  unrestricted tools
summary: >-
  DeepTutor missing MCP tool authorization allows non-admin users to invoke
  unrestricted tools
severity: high
cvss: 8.8
cwe:
  - CWE-862
vendor: deeptutor
product: deeptutor
ecosystem: pip
affected:
  - deeptutor < 1.4.10
patched:
  - deeptutor 1.4.10
published: '2026-06-30'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:27:30Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-jg88-rvpc-qvxj'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58168'
  - url: 'https://github.com/HKUDS/DeepTutor/pull/579'
  - url: >-
      https://github.com/HKUDS/DeepTutor/commit/90046374b3dcd4f8a866d2d64a64440bc08eb2ef
  - url: 'https://github.com/HKUDS/DeepTutor/releases/tag/v1.4.10'
  - url: >-
      https://www.vulncheck.com/advisories/deeptutor-insecure-default-grants-unrestricted-mcp-tool-access-to-non-admin-users
  - url: 'https://github.com/advisories/GHSA-jg88-rvpc-qvxj'
tags:
  - ghsa
  - pip
epss: 0.00597
epssPercentile: 0.4669
ingestedAt: '2026-10-02T22:33:09.858Z'
---

## Overview

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources.

## Affected packages

- `deeptutor < 1.4.10`

## Remediation

Upgrade to a patched release:

- `deeptutor 1.4.10`
