CVE-2026-105791 | Microsoft UFO up to 3.0.8 CommandLineExecutor cli_mcp_server.py bash_command os command injection
A vulnerability labeled as critical has been found in Microsoft UFO up to 3.0.8. Impacted is an unknown function of the file ufo/client/mcp/local_servers/cli_mcp_server.py of the component CommandLineExecutor. Executing a manipulation of the argument bash_command can lead to os command injection.
This vulnerability appears as CVE-2026-105791. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More