Description
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.10, the type_text and launch_app tools in ufo/client/mcp/http_servers/mobile_mcp_server.py pass the authenticated caller-controlled text and package_name parameters into adb shell command argument positions without comprehensive validation. The adb client joins those arguments into a remote command string that the Android shell reparses, allowing shell metacharacters to execute additional commands on an authorized connected device as the Android shell user. Exploitation requires a valid Mobile MCP API key and a reachable device authorized for ADB, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.10.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Command injection on authorized Android device
Action: Patch immediately
AI Analysis

Impact

Microsoft UFO’s type_text and launch_app tools allow an authenticated caller to inject shell metacharacters into the adb command that the Android device executes. The application concatenates the caller‑controlled text and package_name values directly into the adb shell command string without sanitization. As a result, an attacker who possesses a valid Mobile MCP API key and an ADB‑enabled device can execute arbitrary shell commands on the device as the Android shell user. The vulnerability does not provide host‑OS or root privileges, but it enables the attacker to run commands that may read, modify, or exfiltrate data on the device.

Affected Systems

The flaw exists in the Microsoft UFO framework for all releases older than v3.0.10. The affected component is the ufo/client/mcp/http_servers/mobile_mcp_server.py module that implements the Mobile MCP HTTP API. Users running any version prior to 3.0.10 that exposes the type_text or launch_app endpoints to authenticated callers are at risk. The vendor/product affected is Microsoft UFO, an open‑source automation framework that can be used on any platform that supports ADB‑enabled Android devices.

Risk and Exploitability

The CVSS score of 8.8 reflects a high‑severity exploitation that delivers command‑execution privileges. The EPSS score is not available, but the requirement for an authenticated Mobile MCP API key and a reachable, ADB‑authorised device limits the attacker to environments where credentials or device access have already been compromised. Because the exploit does not grant root or host‑OS access, the attack surface is bounded to the Android shell user. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed publicly‑exploited instances yet, but the high severity warrants immediate attention if the affected version is in use.

Generated by OpenCVE AI on October 6, 2026 at 18:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Microsoft UFO to version 3.0.10 or later, which sanitizes the text and package_name arguments in the type_text and launch_app endpoints.
  • Revoke any Mobile MCP API keys that are no longer required and restrict ADB access to only authenticated devices that are explicitly permitted.
  • If upgrading immediately is not possible, disable or remove the type_text and launch_app endpoints from the Mobile MCP API or implement strict input validation that rejects shell metacharacters before forwarding arguments to adb.
  • Enable detailed logging for adb command execution and monitor for anomalous command patterns that may indicate injection attempts.

Generated by OpenCVE AI on October 6, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.10, the type_text and launch_app tools in ufo/client/mcp/http_servers/mobile_mcp_server.py pass the authenticated caller-controlled text and package_name parameters into adb shell command argument positions without comprehensive validation. The adb client joins those arguments into a remote command string that the Android shell reparses, allowing shell metacharacters to execute additional commands on an authorized connected device as the Android shell user. Exploitation requires a valid Mobile MCP API key and a reachable device authorized for ADB, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.10.
Title Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and launch_app
Weaknesses CWE-78
CWE-88
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T15:08:18.093Z

Reserved: 2026-10-05T20:37:19.363Z

Link: CVE-2026-105788

cve-icon Vulnrichment

Updated: 2026-10-06T15:05:28.743Z

cve-icon NVD

Status : Deferred

Published: 2026-10-06T14:17:40.077

Modified: 2026-10-06T16:17:05.597

Link: CVE-2026-105788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')