{"id":"CVE-2026-105790","title":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms","summary":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while…","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-918"],"vendor":"microsoft","product":"UFO","affected":["UFO < 3.0.9"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:18:12.170","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105790","references":[{"url":"https://github.com/microsoft/UFO/commit/f31fb5ef7d07b7825a03fe34b88f1f21cb5cfd35","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.9","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T15:01:49.288Z","slug":"CVE-2026-105790","body":"## Overview\n\nMicrosoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}