Sceawere

Vulnerability Detail

CVE-2026-105790UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft UFO SSRF via Redirect

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
11h ago
Vendor
microsoft
Product
UFO
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-06T14:17:40.490Z",
  "pubdate": "2026-10-06T14:17:40.490Z",
  "executiveSummary": "Microsoft UFO contains a Server-Side Request Forgery (SSRF) vulnerability due to improper handling of WebSocket redirects during device registration.\nPrior to version 3.0.9, the framework failed to enforce pinned_addresses validation after an initial cross-origin redirect, allowing authenticated attackers to direct WebSocket upgrade requests to internal network hosts.\nThis vulnerability is limited to the initiation of TCP connections and handshake requests; it does not permit arbitrary HTTP method execution, sensitive response-body disclosure, or cloud metadata exfiltration.\nThe flaw affects the /api/devices endpoint and the underlying logic in aip/transport/websocket.py.\nExploitation requires the attacker to be an authenticated user with permission to register devices.\nThe risk is categorized as moderate, as it allows attackers to probe the internal infrastructure reachable from the Microsoft UFO server through crafted WebSocket traffic.",
  "technicalDetails": "The vulnerability resides within the device registration flow, specifically involving the /api/devices endpoint and the processing logic in aip/transport/websocket.py.\nThe root cause is an insecure implementation of the websockets.connect() client which performs certificate or address pinning only on the initial destination URI provided during the device registration process.\nWhen a client supplies an attacker-controlled WebSocket endpoint, the server initiates a connection. If the remote endpoint issues a cross-origin redirect (HTTP 3xx status), the websockets.connect() client transparently follows the redirect and initiates a new TCP connection to the destination specified in the Location header.\nThe critical security failure occurs because the server-side pinned_addresses validation logic is applied exclusively to the initial destination. The subsequent connection established as a result of the redirect bypasses this security check entirely.\nThe attack flow follows these stages: 1) An authenticated attacker initiates a device registration request via /api/devices with a malicious WebSocket URI. 2) The server reaches out to the attacker's endpoint, which is configured to return a 301 or 302 redirect pointing to an internal, non-public IP address or hostname. 3) The websockets.connect() client follows the redirect and attempts to upgrade the connection to the internal target. 4) The server opens a new TCP connection and sends the WebSocket upgrade request to the internal host.\nAlthough the server performs a post-handshake peer-IP validation, the initial handshake and TCP connection are already established, allowing the server to interact with internal services before the logic can terminate the invalid session.\nThe impact is strictly defined by the ability of the server to reach out to internal infrastructure. The framework's design prevents the attacker from executing arbitrary HTTP methods against the target, accessing cloud metadata service endpoints, or reading the content of the responses returned by the internal host, thereby limiting the scope of the SSRF to connectivity probing.\nAffected systems include all Microsoft UFO deployments running versions prior to 3.0.9."
}
CVE-2026-105790: Microsoft UFO SSRF via Redirect (MEDIUM Severity, CVSS: 6.4) | Sceawere