CVE-2026-105791

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attacker-influenced agent call can launch an arbitrary executable or script as the desktop user even though the subprocess uses shell=False. Exploitation depends on a user running an affected agent workflow and on inducing the tool call, but successful execution can access or modify that user's files, tokens, and sessions. This issue is fixed in version 3.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
Full discourse1 post
  • Severity Daily@severitydaily

    Microsoft's UFO agent framework allowlisted explorer.exe, which hands its next argument to ShellExecute. The command guard only ever checked the first token. No exploitation reported. https://severitydaily.com/microsoft-ufo-cve-2026-105791-explorer-exe-allowlist-first-token-adb-shell-3-0-9-3-0-10/

    0000031
    32 followersView on X

Explore more