CVE-2026-45366 | universal-tool-calling-protocol typescript-utcp up to 1.1.1 registerManual server-side request forgery (GHSA-r8j5-8747-88cm)
A vulnerability has been found in universal-tool-calling-protocol typescript-utcp up to 1.1.1 and classified as critical. This vulnerability affects the function registerManual. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-45366. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.