{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-25T17:40:05.179","vulnerabilities":[{"cve":{"id":"CVE-2026-62316","sourceIdentifier":"security-advisories@github.com","published":"2026-08-21T21:17:01.350","lastModified":"2026-08-25T15:16:35.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"microsoft","product":"UFO","versions":[{"version":"< 3.0.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T14:19:30.120280Z","id":"CVE-2026-62316","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-346"}]}],"references":[{"url":"https://github.com/microsoft/UFO/commit/3851c5d4e17c2865c56a94a6530692bf6e7a9b02","source":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/releases/tag/v3.0.8","source":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-vf4c-mf32-gf2h","source":"security-advisories@github.com"},{"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-vf4c-mf32-gf2h","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}}]}