CVE-2026-105789: Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the executecommand tool in ufo/client/mcp/httpservers/linuxmcpserver.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft UFOto a version that resolves this vulnerability.Fixed in 3.0.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated caller who can invoke the Linux MCP execute_command tool is required. Exploitation also requires user interaction and a high-complexity attack path, as reflected in the provided CVSS vector.
Are default deployments affected?
The affected behavior is in the Linux MCP server's execute_command tool. The provided information does not establish whether that tool is enabled or exposed in a default deployment.
What can an attacker do with the file-write primitive?
They can create or overwrite files that are writable by the UFO server process by invoking sort -o or supplying uniq's optional output-file operand. This can corrupt configuration or other writable data and disrupt the service; the demonstrated primitive does not directly provide file disclosure or arbitrary code execution.
What should be done if patching is not immediately possible?
Restrict access to authenticated callers that can invoke execute_command, and prevent use of sort output options and uniq's optional output-file operand in command-argument policy. Limit the UFO server process's write permissions to reduce the impact of a successful exploit.
How can I determine whether an installation is affected?
Installations running a version prior to 3.0.9 are affected if they expose the Linux MCP execute_command tool with the described argument handling. Version 3.0.9 contains the fix.