๐Ÿ” CVE Alert

CVE-2026-105789

MEDIUM 5.4

Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.

CWE CWE-88 CWE-184
Vendor microsoft
Product ufo
Ecosystems
Industries
TechnologyEnterprise
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft ufo

Be the first to know when new medium vulnerabilities affecting microsoft ufo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

microsoft / UFO
< 3.0.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/UFO/security/advisories/GHSA-85w2-wggf-rw49 github.com: https://github.com/microsoft/UFO/pull/349 github.com: https://github.com/microsoft/UFO/commit/4f793622794f5d47810d54bed431c61f6a781dd6 github.com: https://github.com/microsoft/UFO/releases/tag/v3.0.9