CVE-2026-45322: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in microsoft UFO
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string from action parameters directly to subprocess.Popen() with shell=True and executable=powershell.exe. The same shell-execution behavior is also reachable through ShellReceiver.execute_command(). The shell receiver is invoked by action classes such as RunShellCommand.execute() and ExecuteCommand.execute(), which forward stored action parameters to the shell receiver. Because UFO stores planned and executed actions in per-session JSON records, an attacker who can write or modify a session/action JSON file can plant a shell action. When the session is resumed or replayed, UFO executes the attacker's command as the UFO process user.
AI Analysis
Technical Summary
Microsoft UFO, an open-source framework for intelligent automation, has an OS command injection vulnerability (CWE-78) in tagged releases up to and including version 3.0.0. The issue occurs in the shell action replay path where ShellReceiver.run_shell() and ShellReceiver.execute_command() invoke subprocess.Popen() with shell=True and PowerShell as the executable, passing unsanitized command strings from action parameters. Because UFO stores planned and executed actions in per-session JSON files, an attacker able to write or modify these JSON files can plant shell commands that execute upon session replay, running with the privileges of the UFO process user. This vulnerability is exploitable locally with low privileges and does not require user interaction.
Potential Impact
Successful exploitation allows an attacker with write access to session or action JSON files to execute arbitrary commands on the host system with the permissions of the UFO process user. This can lead to full compromise of the affected system, including confidentiality, integrity, and availability impacts. The CVSS score of 7.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict write access to session and action JSON files to trusted users only to prevent unauthorized modification. Monitor for suspicious modifications to these files and avoid resuming or replaying sessions from untrusted sources.
CVE-2026-45322: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in microsoft UFO
Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string from action parameters directly to subprocess.Popen() with shell=True and executable=powershell.exe. The same shell-execution behavior is also reachable through ShellReceiver.execute_command(). The shell receiver is invoked by action classes such as RunShellCommand.execute() and ExecuteCommand.execute(), which forward stored action parameters to the shell receiver. Because UFO stores planned and executed actions in per-session JSON records, an attacker who can write or modify a session/action JSON file can plant a shell action. When the session is resumed or replayed, UFO executes the attacker's command as the UFO process user.
CVSS v3.1
Score 7.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft UFO, an open-source framework for intelligent automation, has an OS command injection vulnerability (CWE-78) in tagged releases up to and including version 3.0.0. The issue occurs in the shell action replay path where ShellReceiver.run_shell() and ShellReceiver.execute_command() invoke subprocess.Popen() with shell=True and PowerShell as the executable, passing unsanitized command strings from action parameters. Because UFO stores planned and executed actions in per-session JSON files, an attacker able to write or modify these JSON files can plant shell commands that execute upon session replay, running with the privileges of the UFO process user. This vulnerability is exploitable locally with low privileges and does not require user interaction.
Potential Impact
Successful exploitation allows an attacker with write access to session or action JSON files to execute arbitrary commands on the host system with the permissions of the UFO process user. This can lead to full compromise of the affected system, including confidentiality, integrity, and availability impacts. The CVSS score of 7.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict write access to session and action JSON files to trusted users only to prevent unauthorized modification. Monitor for suspicious modifications to these files and avoid resuming or replaying sessions from untrusted sources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-11T20:50:30.539Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a176dbbe29bf47b50f73d7a
Added to database: 05/27/2026, 22:18:35 UTC
Last enriched: 05/27/2026, 22:34:00 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.