{"id":"CVE-2026-105792","title":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms","summary":"Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-833"],"vendor":"microsoft","product":"UFO","affected":["UFO < 3.0.9"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:25:00.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105792","references":[{"url":"https://github.com/microsoft/UFO/commit/0eeb792333ce76c856bc1c8b05fd65fc26bd3c50","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.9","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-3hwr-qx8m-9xxx","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T15:01:49.306Z","slug":"CVE-2026-105792","body":"## Overview\n\nMicrosoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires a non-reentrant lock and then calls SessionManager.get_result() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}