CVE-2026-62316Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-23: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 108-23
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Innora.ai@Innora_sg
    Disclosure

    CVE-2026-62316 (CVSS 8.8): Microsoft UFO linux_mcp_server.py FastMCP streamable HTTP on localhost:8010 — no Host/Origin/Sec-Fetch-Site bind. DNS-rebind a page to local /mcp → invoke execute_command as local user. Fixed in 3.0.8. Found by AAtomical. #CVE #MCP #AppSec #InfoSec https://t.co/3cZph8rPOy

    Post summary

    The tweet announces CVE-2026-62316, a CVSS 8.8 flaw in Microsoft UFO’s linux_mcp_server.py that allows DNS‑rebind based command execution on localhost, which has been fixed in version 3.0.8.

    00000101
    23 followersView on X

Explore more