Arbitrary Command Execution Vulnerability in UI-TARS-desktop by ByteDance
CVE-2026-81735
What is CVE-2026-81735?
The mcp-http-server package in the UI-TARS-desktop application is susceptible to an arbitrary command execution vulnerability due to its default listen address being set to '::', binding to every network interface. The authentication middleware for the service is optional and only applies when explicitly provided by the caller. This oversight allows any unauthenticated client that can reach the service to execute arbitrary commands, posing a significant security risk. The issue emerged from specific entry points in the system that bypassed authentication entirely, exposing critical functionalities such as command execution and file management without appropriate credentials.
Affected Version(s)
UI-TARS-desktop 0
UI-TARS-desktop c2ad42e3eb9b27830db41a3e6f51ca7179d9b168
