CVE-2026-105790: Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinning via redirects
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinnedaddresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft UFOto a version that resolves this vulnerability.Fixed in 3.0.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to be authenticated and able to register a Galaxy device through the /api/devices endpoint. They must control a WebSocket endpoint that is permitted by the initial address-pinning checks and can redirect the client to an internal host reachable by the UFO server.
Are default deployments affected?
The available information does not establish whether the vulnerable Galaxy device-registration workflow or its relevant WebSocket configuration is enabled by default. Exposure depends on authenticated access to /api/devices and the server being able to reach internal redirect targets.
What is the actual impact of a successful exploit?
The confirmed impact is that the server makes an internal TCP connection and sends a WebSocket handshake request to the redirected host. The issue does not confirm arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access.
What should teams do if they cannot upgrade immediately?
Restrict authenticated access to device registration and limit the UFO server's network reachability to internal systems that should not receive WebSocket connections. The issue is fixed in version 3.0.9.
How can teams identify potentially affected systems?
Systems running a version prior to 3.0.9 that allow authenticated Galaxy device registration through /api/devices are potentially affected. Review registration activity and outbound connections for WebSocket handshakes to unexpected internal destinations following connections to attacker-controlled endpoints.