CVE-2026-105790 | Microsoft UFO up to 3.0.8 WebSocket Transport websocket.py websockets.connect cross-domain policy (EUVD-2026-93407)
A vulnerability was found in Microsoft UFO up to 3.0.8 and classified as problematic. Affected is the function websockets.connect of the file aip/transport/websocket.py of the component WebSocket Transport. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is tracked as CVE-2026-105790. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More