CVE-2026-105791 | Microsoft UFO up to 3.0.8 CommandLineExecutor cli_mcp_server.py bash_command os command injection

SecurityVulns

A vulnerability labeled as critical has been found in Microsoft UFO up to 3.0.8. Impacted is an unknown function of the file ufo/client/mcp/local_servers/cli_mcp_server.py of the component CommandLineExecutor. Executing a manipulation of the argument bash_command can lead to os command injection.

This vulnerability appears as CVE-2026-105791. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More