Disclosure summary
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-jg88-rvpc-qvxj
Open original source · Updated Oct 02, 2026
DeepTutor missing MCP tool authorization allows non-admin users to invoke unrestricted tools
Source severity: HIGH / 7.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | deeptutor | < 1.4.10 | 1.4.10 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-06-30T14:31:38-04:00
MODIFIED 2026-10-02T14:27:30-04:00
INGESTED 2026-10-06T11:45:17-04:00