CVE-2026-105789: Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool

Published Oct 6, 2026
·
Updated

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the executecommand tool in ufo/client/mcp/httpservers/linuxmcpserver.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.

Affected Software

1 affected component
Microsoft UFO<3.0.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Microsoft UFO to a version that resolves this vulnerability.

    Fixed in 3.0.9

Event History

Oct 6, 2026
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated caller who can invoke the Linux MCP execute_command tool is required. Exploitation also requires user interaction and a high-complexity attack path, as reflected in the provided CVSS vector.

2

Are default deployments affected?

The affected behavior is in the Linux MCP server's execute_command tool. The provided information does not establish whether that tool is enabled or exposed in a default deployment.

3

What can an attacker do with the file-write primitive?

They can create or overwrite files that are writable by the UFO server process by invoking sort -o or supplying uniq's optional output-file operand. This can corrupt configuration or other writable data and disrupt the service; the demonstrated primitive does not directly provide file disclosure or arbitrary code execution.

4

What should be done if patching is not immediately possible?

Restrict access to authenticated callers that can invoke execute_command, and prevent use of sort output options and uniq's optional output-file operand in command-argument policy. Limit the UFO server process's write permissions to reduce the impact of a successful exploit.

5

How can I determine whether an installation is affected?

Installations running a version prior to 3.0.9 are affected if they expose the Linux MCP execute_command tool with the described argument handling. Version 3.0.9 contains the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203