Overview
A critical command injection vulnerability has been disclosed in Microsoft UFO, an open-source framework for intelligent automation across devices and platforms. Tracked as CVE-2026-105793 with a CVSS score of 9.1, the flaw sits in UFO's mobile Model Context Protocol (MCP) server and lets an attacker who can reach the press_key tool execute arbitrary commands on the shell of any Android device connected via ADB.
The vulnerable code lives in ufo/client/mcp/http_servers/mobile_mcp_server.py. The press_key tool accepts a free-form key_code parameter and passes it, unsanitized, into an adb shell input keyevent call.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105793 |
| Severity | Critical (CVSS 9.1) |
| CWE | CWE-78 — OS Command Injection |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L |
| Attack Vector | Network |
| Privileges Required | Low (valid MCP API key) |
| User Interaction | None |
| Impact | Arbitrary command execution in the Android shell context |
| Affected Versions | Before 3.0.9 |
| Fixed Version | 3.0.9 |
| Advisory | GHSA-5cjx-4375-4877 |
How It Works
UFO's mobile MCP HTTP server exposes a press_key tool intended to simulate a single Android key event (home, back, volume, etc.) by shelling out to adb shell input keyevent <key_code>. The key_code value supplied by the MCP client is forwarded to the adb client without validation or escaping.
Because the value ends up concatenated into a shell command, an attacker who can call press_key — which only requires a valid UFO_MCP_API_KEY rather than any stronger authorization — can supply shell metacharacters instead of a numeric key code. The adb client's argument handling allows those metacharacters to break out of the intended input keyevent invocation and execute arbitrary additional commands inside the Android shell running on the connected device.
A sibling issue, CVE-2026-105788, affects the same file's text and package_name parameters and should be remediated alongside this bug.
Impact Assessment
Who Is At Risk
Any deployment of UFO's mobile MCP HTTP server where:
- A physical or virtual Android device is connected and reachable via
adb - The
press_keyMCP tool is exposed to any client holding (or able to obtain) a valid MCP API key - Automation pipelines or AI agents are wired to call UFO's mobile tools on untrusted or semi-trusted input
Potential Attack Chains
- API key acquisition — Attacker obtains or brute-forces a valid
UFO_MCP_API_KEY, or abuses a service that proxies untrusted input into UFO's MCP tool calls - Malicious key_code submission — Attacker calls
press_keywith a crafted value containing shell metacharacters instead of a legitimate key code - Command execution — The adb client executes the injected commands in the context of the Android device's shell user
- Post-exploitation — Depending on device configuration, the attacker can read app data, install packages, exfiltrate files, or pivot to other automation performed by the same UFO instance
The impact is bounded to the Android-shell-user context on the targeted device — this is not a host-OS escape on the machine running the MCP server — but for device farms, mobile test labs, or automation fleets, that's still enough to compromise every app and dataset reachable from that shell.
Mitigation
Immediate Actions
- Upgrade to Microsoft UFO 3.0.9 or later, which sanitizes/validates the
key_codeparameter before invokingadb - Rotate all
UFO_MCP_API_KEYvalues in case keys were exposed or guessed prior to patching - Restrict network exposure of the mobile MCP HTTP server to trusted automation hosts only — it should not be reachable from the open internet
Detection Opportunities
- Review
adbcommand history or process logs on hosts running UFO's mobile MCP server forinput keyeventinvocations containing unexpected characters (quotes, semicolons, pipes, backticks) - Monitor for unexpected package installs, file access, or shell activity on Android devices automated through UFO
Defence-in-Depth
- Treat all MCP tool parameters as untrusted input, even from authenticated callers — validate numeric fields strictly
- Isolate automation device farms on segmented networks so a compromised shell can't reach unrelated infrastructure
- Apply least-privilege scoping to MCP API keys where UFO's tooling supports it
Discovery & Disclosure
CVE-2026-105793 was published October 6, 2026, alongside the related CVE-2026-105788. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed. Given the low bar for exploitation — any party capable of calling press_key can attempt injection — upgrading promptly is recommended rather than waiting for confirmed in-the-wild exploitation.