PT-2026-106748 · Microsoft · Ufo

CVE-2026-105791

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft UFO versions prior to 3.0.9
Description The run shell tool within the CommandLineExecutor component of ufo/client/mcp/local servers/cli mcp server.py incorrectly validates the bash command parameter by only checking the first token. Because explorer.exe is permitted, an attacker can leverage the way Windows delegates path arguments to ShellExecute to launch arbitrary executables or scripts as the desktop user, bypassing the shell=False subprocess restriction. Successful exploitation allows access to or modification of the user's files, tokens, and sessions, provided the user runs an affected agent workflow and the tool call is induced.
Recommendations Update to version 3.0.9. As a temporary workaround, restrict the use of the run shell tool in the CommandLineExecutor component.

Exploit

Fix

Incomplete List of Disallowed Inputs

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105791
GHSA-CMQ9-VQJF-4Q2Q

Affected Products

Ufo