PT-2026-41124 · Pypi · Python-Utcp

Zeroxjacks

·

Published

2026-05-14

·

Updated

2026-05-15

·

CVE-2026-45370

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions python-utcp versions prior to 1.1.3
Description The prepare environment() function in cli communication protocol.py passes a complete copy of os.environ to every CLI subprocess. This allows any environment variable in the host process, such as cloud provider credentials, database connection strings, and LLM API keys, to be accessible to injected commands. When combined with a command injection flaw in the substitute utcp args() function, an attacker can exfiltrate all process-level secrets in a single tool call.
Recommendations Update to version 1.1.3 or newer.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-45370
GHSA-5V57-8RXJ-3P2R

Affected Products

Python-Utcp