CVE-2026-58168 - DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users
CVE ID :CVE-2026-58168 Published : June 30, 2026, 3:52 p.m. | 1 hour, 20 minutes ago Description :DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning...