CVE-2026-58168: DeepTutor authorization bypass grants unrestricted MCP tool access
DeepTutor before 1.4.10 contained an authorization bypass in its multi-user tool access control, where allowed_mcp_tools returned None instead of a denial when mcp_tools was omitted from a user's grant. Low-privilege users or prompt-injected content in a user session could enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers.
Disclosed 30 June 2026 · Record updated 13 September 2026
Impact
Low-privilege users, or attackers using prompt-injected content within a user session, could invoke any configured MCP tool (filesystem, shell, browser servers), gaining unauthorized access to sensitive deployment resources.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-58168
