SECURITYCRITICALCVE-2026-105793

CVE-2026-105793: Command Injection in Microsoft UFO's Mobile MCP Server via Unsanitized ADB Key Codes

A flaw in Microsoft UFO's mobile MCP server lets attackers inject arbitrary ADB shell commands on connected Android devices.

Dylan H.

Security Team

October 7, 2026
4 min read
CVE-2026-105793: Command Injection in Microsoft UFO's Mobile MCP Server via Unsanitized ADB Key Codes

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Microsoft UFO before 3.0.9

Overview

A critical command injection vulnerability has been disclosed in Microsoft UFO, an open-source framework for intelligent automation across devices and platforms. Tracked as CVE-2026-105793 with a CVSS score of 9.1, the flaw sits in UFO's mobile Model Context Protocol (MCP) server and lets an attacker who can reach the press_key tool execute arbitrary commands on the shell of any Android device connected via ADB.

The vulnerable code lives in ufo/client/mcp/http_servers/mobile_mcp_server.py. The press_key tool accepts a free-form key_code parameter and passes it, unsanitized, into an adb shell input keyevent call.


Technical Details

FieldValue
CVE IDCVE-2026-105793
SeverityCritical (CVSS 9.1)
CWECWE-78 — OS Command Injection
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Attack VectorNetwork
Privileges RequiredLow (valid MCP API key)
User InteractionNone
ImpactArbitrary command execution in the Android shell context
Affected VersionsBefore 3.0.9
Fixed Version3.0.9
AdvisoryGHSA-5cjx-4375-4877

How It Works

UFO's mobile MCP HTTP server exposes a press_key tool intended to simulate a single Android key event (home, back, volume, etc.) by shelling out to adb shell input keyevent <key_code>. The key_code value supplied by the MCP client is forwarded to the adb client without validation or escaping.

Because the value ends up concatenated into a shell command, an attacker who can call press_key — which only requires a valid UFO_MCP_API_KEY rather than any stronger authorization — can supply shell metacharacters instead of a numeric key code. The adb client's argument handling allows those metacharacters to break out of the intended input keyevent invocation and execute arbitrary additional commands inside the Android shell running on the connected device.

A sibling issue, CVE-2026-105788, affects the same file's text and package_name parameters and should be remediated alongside this bug.


Impact Assessment

Who Is At Risk

Any deployment of UFO's mobile MCP HTTP server where:

  • A physical or virtual Android device is connected and reachable via adb
  • The press_key MCP tool is exposed to any client holding (or able to obtain) a valid MCP API key
  • Automation pipelines or AI agents are wired to call UFO's mobile tools on untrusted or semi-trusted input

Potential Attack Chains

  1. API key acquisition — Attacker obtains or brute-forces a valid UFO_MCP_API_KEY, or abuses a service that proxies untrusted input into UFO's MCP tool calls
  2. Malicious key_code submission — Attacker calls press_key with a crafted value containing shell metacharacters instead of a legitimate key code
  3. Command execution — The adb client executes the injected commands in the context of the Android device's shell user
  4. Post-exploitation — Depending on device configuration, the attacker can read app data, install packages, exfiltrate files, or pivot to other automation performed by the same UFO instance

The impact is bounded to the Android-shell-user context on the targeted device — this is not a host-OS escape on the machine running the MCP server — but for device farms, mobile test labs, or automation fleets, that's still enough to compromise every app and dataset reachable from that shell.


Mitigation

Immediate Actions

  • Upgrade to Microsoft UFO 3.0.9 or later, which sanitizes/validates the key_code parameter before invoking adb
  • Rotate all UFO_MCP_API_KEY values in case keys were exposed or guessed prior to patching
  • Restrict network exposure of the mobile MCP HTTP server to trusted automation hosts only — it should not be reachable from the open internet

Detection Opportunities

  • Review adb command history or process logs on hosts running UFO's mobile MCP server for input keyevent invocations containing unexpected characters (quotes, semicolons, pipes, backticks)
  • Monitor for unexpected package installs, file access, or shell activity on Android devices automated through UFO

Defence-in-Depth

  • Treat all MCP tool parameters as untrusted input, even from authenticated callers — validate numeric fields strictly
  • Isolate automation device farms on segmented networks so a compromised shell can't reach unrelated infrastructure
  • Apply least-privilege scoping to MCP API keys where UFO's tooling supports it

Discovery & Disclosure

CVE-2026-105793 was published October 6, 2026, alongside the related CVE-2026-105788. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed. Given the low bar for exploitation — any party capable of calling press_key can attempt injection — upgrading promptly is recommended rather than waiting for confirmed in-the-wild exploitation.


References