AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)

AutoJack: Single-Page RCE Against Hosts Running AI Agents (TL-2026-0862), also tracked as AutoJack, is a high-severity software vulnerability, first published 2026-06-18. It has no confirmed attribution, affects Microsoft AutoGen Studio (autogenstudio), maps to 12 MITRE ATT&CK techniques (T1021, T1046, T1059), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-0862

Threat ID
TL-2026-0862
Also known as
AutoJack
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
2026-06-18
Last reviewed
2026-06-18
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software development, artificial intelligence
Target regions
Global
Detection rules
9
Indicators of compromise
19

Malware and tooling in AutoJack: Single-Page RCE Against Hosts Running AI Agents

Malware and tooling: AutoGen Studio (autogenstudio)

AutoJack is a Microsoft-documented exploit chain in AutoGen Studio in which a single untrusted web page, rendered by an AutoGen browsing agent, reaches the local Model Context Protocol (MCP) WebSocket and spawns arbitrary host processes. The browsing agent is abused as a confused deputy to cross the localhost trust boundary and achieve remote code execution.

How AutoJack: Single-Page RCE Against Hosts Running AI Agents works

Microsoft Defender Security Research disclosed AutoJack, a three-vulnerability chain that turns an AI agent framework into a single-page remote code execution (RCE) primitive. The target is AutoGen Studio, the low-code multi-agent prototyping UI built on Microsoft's AutoGen framework. The chain weaponizes an AutoGen browsing agent (e.g., MultimodalWebSurfer / Playwright-driven web surfer) as a confused deputy: when the agent is instructed to visit an attacker-controlled page, the JavaScript on that page executes within a browser context that inherits the host's localhost origin, allowing it to reach loopback-only services that assume same-origin requests are trustworthy.

The first link is an origin-allowlist bypass (CWE-1385, Missing Origin Validation in WebSockets): the AutoGen Studio MCP WebSocket accepts connections whose Origin is http://127.0.0.1 or http://localhost, but content rendered by the local browsing agent inherits exactly that origin, defeating the check. The second link is missing authentication (CWE-306, Missing Authentication for Critical Function): the application's auth middleware explicitly skips paths matching /api/mcp/* and /api/ws/* on the assumption those handlers enforce their own authentication, but the MCP WebSocket handler never did, so the endpoint is reachable without credentials regardless of the configured auth mode (github, msal, or firebase). The third link is command injection (CWE-78, OS Command Injection): the WebSocket endpoint accepts a server_params query parameter holding base64-encoded JSON that is deserialized directly into a StdioServerParams object with no command allowlisting, so an attacker supplies an arbitrary command to execute. A demonstration payload of {"type":"StdioServerParams","command":"calc.exe","args":[],"env":{"pwned":"true"}} launches calc.exe on the host; any executable and arguments can be substituted.

The end-to-end flow: the operator's browsing agent is steered (via prompt injection embedded in the page or task) to a malicious URL; the page's JavaScript scans loopback ports, opens ws://localhost:8081/api/mcp/ws/?server_params=<base64> to the unauthenticated MCP socket, and the server decodes the parameters and spawns the attacker-chosen process as a stdio MCP server — full RCE in the context of the AutoGen Studio process.

Scope is narrow and the issue was never shipped: only development builds from the AutoGen repository main branch, between the MCP plugin landing and the hardening commit, contain the vulnerable /api/mcp/ws route. Published PyPI releases (current 0.4.2.2 at disclosure) do not include the MCP WebSocket route and are not affected. Microsoft states the chain was identified and remediated before any vulnerable code reached a PyPI release, and it was not exploited in the wild. The fix (commit b047730) introduces server-side parameter binding — a POST to /api/mcp/ws/connect stores parameters server-side under a UUID so they can no longer be injected through the URL — and tightens the middleware skip list so /api/mcp no longer bypasses authentication. AutoJack is documented here as a novel agentic-RCE TTP warranting detection guidance even absent in-the-wild exploitation.

MITRE ATT&CK techniques used in TL-2026-0862

Lateral Movement

T1021 Remote Services

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

stealth

T1684.001 Impersonation

Affected products and versions in AutoJack: Single-Page RCE Against Hosts Running AI Agents

  • Microsoft — AutoGen Studio (autogenstudio)
    Vulnerable versions: main-branch development builds between the MCP plugin landing commit and hardening commit b047730
    Fixed in: main-branch commit b047730 and later; PyPI releases (0.4.2.2 and other published packages — the MCP WebSocket route was never shipped to PyPI)

Remediation for AutoJack: Single-Page RCE Against Hosts Running AI Agents

Patches

  • AutoGen main-branch hardening commit b047730 (server-side parameter binding + tighter auth skip list)

Immediate actions

  • Update AutoGen Studio development builds to main-branch commit b047730 or later, which adds server-side parameter binding for the MCP WebSocket and removes /api/mcp from the auth-middleware skip list
  • Stay on published PyPI releases (>=0.4.2.2), which do not include the vulnerable /api/mcp/ws route
  • Bind AutoGen Studio to loopback only and add host firewall rules blocking non-loopback access to port 8081
  • Do not let a browsing/web-surfer agent and the developer share the same host as a privileged MCP-enabled AutoGen Studio instance

Workarounds

  • Disable or remove the MCP WebSocket plugin / route on affected development builds
  • Allowlist permitted MCP server executables instead of accepting arbitrary StdioServerParams.command
  • Disable browsing/web-surfer agent capabilities when running a privileged AutoGen Studio instance

Longer-term hardening

  • Place AutoGen Studio behind an authenticated reverse proxy that enforces authentication on ALL paths, including /api/mcp/* and /api/ws/*
  • Run AutoGen Studio under a low-privilege account inside a sandboxed user profile (e.g., Windows Sandbox, Microsoft Dev Box)
  • Separate the agent browsing identity from the developer identity (distinct Microsoft Entra Agent ID)
  • Deploy untrusted-content-rendering agents only in isolated, disposable developer prototype environments
  • Apply prompt-injection defenses (e.g., Azure AI Content Safety Prompt Shields) to content fed to browsing agents

Weaknesses (CWE) in AutoJack: Single-Page RCE Against Hosts Running AI Agents

CWE-1385, CWE-306, CWE-78

Timeline of AutoJack: Single-Page RCE Against Hosts Running AI Agents

  • Precedent: CVE-2025-52882 (WebSocket authentication bypass in Claude Code IDE extensions) demonstrated unauthenticated localhost WebSocket RCE, establishing the missing-origin-validation + missing-auth pattern AutoJack reuses against AutoGen Studio's MCP socket.
  • Precedent for the localhost-MCP attack class: CVE-2025-49596 (MCP Inspector drive-by localhost RCE) was disclosed, showing untrusted web content reaching a loopback MCP service — the same trust-boundary failure AutoJack later weaponizes via an AI browsing agent.
  • Microsoft published companion research, 'When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps', framing the class of AI-app trust-boundary and configuration flaws that AutoJack exemplifies.
  • Microsoft published Defender advanced hunting queries for AutoGen Studio child processes, MCP WebSocket connections carrying server_params, and browser-automation agents reaching non-corporate domains.
  • Microsoft confirmed the issue was identified and remediated before any vulnerable code shipped to a PyPI release and was not exploited in the wild.
  • Only main-branch development builds between the MCP plugin landing and commit b047730 are affected; published PyPI releases (current 0.4.2.2) never included the /api/mcp/ws route and are not affected.
  • Remediation merged on the AutoGen main branch (commit b047730): server-side parameter binding via POST /api/mcp/ws/connect (UUID-keyed) and removal of /api/mcp from the auth-middleware skip list.
  • Proof-of-concept demonstrated host process execution via a base64 StdioServerParams payload spawning calc.exe with env pwned=true through ws://localhost:8081/api/mcp/ws/.
  • The three-link chain was documented: origin-allowlist bypass (CWE-1385), missing MCP authentication (CWE-306), and command injection via the server_params query parameter (CWE-78).
  • Microsoft Defender Security Research publicly disclosed the AutoJack exploit chain against AutoGen Studio in the Microsoft Security Blog.

Sources cited for AutoJack: Single-Page RCE Against Hosts Running AI Agents

Threats related to AutoJack: Single-Page RCE Against Hosts Running AI Agents

Detection coverage for TL-2026-0862

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0862 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats