← Back to CVE List
CVE-2026-105790NVD
Vulnerability Summary
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.
CVSS v3.1 Base Metrics — Score 6.4 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/microsoft/UFO/commit/f31fb5ef7d07b7825a03fe34b88f1f21cb5cfd35
- https://github.com/microsoft/UFO/releases/tag/v3.0.9
- https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27
- https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27
- https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27
- https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27
- https://github.com/microsoft/UFO/security/advisories/GHSA-3pgm-xw75-hq27