---
id: CVE-2026-105789
title: >-
  Microsoft UFO is an open-source framework for intelligent automation across
  devices and platforms
summary: >-
  Microsoft UFO is an open-source framework for intelligent automation across
  devices and platforms. Prior to 3.0.9, the execute_command tool in
  ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as
  read-only commands whi…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L'
cwe:
  - CWE-88
  - CWE-184
vendor: microsoft
product: UFO
affected:
  - UFO < 3.0.9
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:18:12.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105789'
references:
  - url: >-
      https://github.com/microsoft/UFO/commit/4f793622794f5d47810d54bed431c61f6a781dd6
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/UFO/pull/349'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/UFO/releases/tag/v3.0.9'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/UFO/security/advisories/GHSA-85w2-wggf-rw49'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T14:34:10.551669Z'
ingestedAt: '2026-10-06T15:01:49.287Z'
---

## Overview

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
