← Back to CVE List
Vulnerability Intelligence Report
Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool

CVE-2026-105789

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.

No Active Exploit Signals
CVSS Base Score
5.4
MEDIUM
Exploitability:1.2
Impact Score:4.3
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-88 ↗CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CWE-184 ↗CWE-184: Incomplete List of Disallowed Inputs

Affected Products & Versions

Vendor Product Affected Versions
microsoft UFO < 3.0.9 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-10-05T20:37:19
Published2026-10-06T14:07:25
Last Updated2026-10-06T14:47:07

LINK COPIED TO CLIPBOARD