CVE-2026-105790 PUBLISHED

Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinning via redirects

Assigner: GitHub_M
Reserved: 05.10.2026 Published: 06.10.2026 Updated: 06.10.2026

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 6.4

Product Status

Vendor microsoft
Product UFO
Versions
  • Version < 3.0.9 is affected

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE