Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105797— SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)

Quick assessment

Affected
microsoft simplechat
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SimpleChat 是一款安全的 AI 对话应用程序,支持个人和团队工作区,并提供基于文档的交互功能。在版本 0.261.003 和 0.261.027 中,POST /api/user/plugins 接口存在一个授权顺序缺陷(authorization ordering flaw),使得经过身份验证的低权限用户可以省略顶层的 MCP(Model Context Protocol)类型字段,从而绕过 _reject_non_admin_mcp_stdio 检查。这是因为该检查发生在从元数据中恢复类型之前。 随后

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105797

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)
Source: CVE Program / CVE List V5
Vulnerability Description
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored personal action can then reach McpPluginFactory.create_connector, and MCPStdioPlugin.connect starts the attacker-selected operating-system process under the application service identity when the action tool is invoked. Exploitation requires personal plugins to be enabled and governance to permit MCP actions, and it can expose or modify secrets and data available to the service or disrupt the service. This issue is fixed in version 0.261.031.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
microsoft simplechat < 0.261.031 -

II. Public POCs for CVE-2026-105797

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105797

请登录查看更多情报信息。

Other References for CVE-2026-105797 (2)

Same Patch Batch · microsoft · 2026-10-06 · 11 CVEs total

CVE-2026-105794 9.1 CRITICAL MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
CVE-2026-105793 9.1 CRITICAL Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key`
CVE-2026-105796 8.8 HIGH Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP gene
CVE-2026-105788 8.8 HIGH Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and l
CVE-2026-105798 8.7 HIGH SimpleChat: Stored XSS via group document filename in inline onclick handler
CVE-2026-105791 7.5 HIGH Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injecti
CVE-2026-105792 6.5 MEDIUM Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager
CVE-2026-105790 6.4 MEDIUM Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinni
CVE-2026-105789 5.4 MEDIUM Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool
CVE-2026-105795 3.1 LOW Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests

IV. Related Vulnerabilities

V. Comments for CVE-2026-105797

No comments yet


Leave a comment