CVE-2026-105788 | Microsoft UFO up to 3.0.9 Mobile MCP Server mobile_mcp_server.py text/package_name os command injection (EUVD-2026-93405)
A vulnerability has been found in Microsoft UFO up to 3.0.9 and classified as critical. This impacts an unknown function of the file ufo/client/mcp/http_servers/mobile_mcp_server.py of the component Mobile MCP Server. Performing a manipulation of the argument text/package_name results in os command injection.
This vulnerability is identified as CVE-2026-105788. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More