Command Injection in Microsoft UFO Framework Affects Windows Users
CVE-2026-105791
What is CVE-2026-105791?
The Microsoft UFO framework, an open-source tool for intelligent automation, is susceptible to a command injection vulnerability in the run_shell tool of the CommandLineExecutor component. This flaw affects all versions prior to 3.0.9. The vulnerability arises due to inadequate validation of the bash_command parameter, which permits the execution of explorer.exe. Since explorer.exe can delegate path arguments to ShellExecute, a malicious agent could exploit this weakness, allowing unauthorized execution of arbitrary executables or scripts under the privileged context of the desktop user. This exploitation relies on a user running an affected agent workflow and can potentially allow attackers to access or manipulate sensitive files, tokens, and active sessions of the user. The issue has been resolved in version 3.0.9.
Affected Version(s)
UFO < 3.0.9