PT-2026-106748 · Microsoft · Ufo
CVE-2026-105791
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft UFO versions prior to 3.0.9
Description
The
run shell tool within the CommandLineExecutor component of ufo/client/mcp/local servers/cli mcp server.py incorrectly validates the bash command parameter by only checking the first token. Because explorer.exe is permitted, an attacker can leverage the way Windows delegates path arguments to ShellExecute to launch arbitrary executables or scripts as the desktop user, bypassing the shell=False subprocess restriction. Successful exploitation allows access to or modification of the user's files, tokens, and sessions, provided the user runs an affected agent workflow and the tool call is induced.Recommendations
Update to version 3.0.9.
As a temporary workaround, restrict the use of the
run shell tool in the CommandLineExecutor component.Exploit
Fix
Incomplete List of Disallowed Inputs
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ufo