CVE-2026-105789: falha de média gravidade em microsoft UFO
Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.4epss 0.7%
probabilidade de exploração
0.7%top 48% das CVEs
exploração observada
nãonenhuma fonte reporta
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L
Produtos afetados
microsoft · UFOCVEs relacionadas — microsoft UFO
No mesmo produto, das mais perigosas para as menos.
CVE-2026-73296CRITICALMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosureEPSS 3.7%CVE-2026-73297MEDIUMMicrosoft UFO: IPv6 transition address bypass of SSRF guard in URL validationEPSS 2.9%CVE-2026-45322HIGHOS Command Injection in Microsoft UFO Shell Action Replay via Stored Session JSONEPSS 2.1%CVE-2026-55440MEDIUMMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of serviceEPSS 1.3%CVE-2026-105788HIGHMicrosoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and launch_appEPSS 1.1%CVE-2026-46402HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directoryEPSS 1.0%