AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)
AutoJack: Single-Page RCE Against Hosts Running AI Agents (TL-2026-0862), also tracked as AutoJack, is a high-severity software vulnerability, first published 2026-06-18. It has no confirmed attribution, affects Microsoft AutoGen Studio (autogenstudio), maps to 12 MITRE ATT&CK techniques (T1021, T1046, T1059), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-0862
- Threat ID
- TL-2026-0862
- Also known as
- AutoJack
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-06-18
- Last reviewed
- 2026-06-18
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, artificial intelligence
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in AutoJack: Single-Page RCE Against Hosts Running AI Agents
Malware and tooling: AutoGen Studio (autogenstudio)
AutoJack is a Microsoft-documented exploit chain in AutoGen Studio in which a single untrusted web page, rendered by an AutoGen browsing agent, reaches the local Model Context Protocol (MCP) WebSocket and spawns arbitrary host processes. The browsing agent is abused as a confused deputy to cross the localhost trust boundary and achieve remote code execution.
How AutoJack: Single-Page RCE Against Hosts Running AI Agents works
Microsoft Defender Security Research disclosed AutoJack, a three-vulnerability chain that turns an AI agent framework into a single-page remote code execution (RCE) primitive. The target is AutoGen Studio, the low-code multi-agent prototyping UI built on Microsoft's AutoGen framework. The chain weaponizes an AutoGen browsing agent (e.g., MultimodalWebSurfer / Playwright-driven web surfer) as a confused deputy: when the agent is instructed to visit an attacker-controlled page, the JavaScript on that page executes within a browser context that inherits the host's localhost origin, allowing it to reach loopback-only services that assume same-origin requests are trustworthy.
The first link is an origin-allowlist bypass (CWE-1385, Missing Origin Validation in WebSockets): the AutoGen Studio MCP WebSocket accepts connections whose Origin is http://127.0.0.1 or http://localhost, but content rendered by the local browsing agent inherits exactly that origin, defeating the check. The second link is missing authentication (CWE-306, Missing Authentication for Critical Function): the application's auth middleware explicitly skips paths matching /api/mcp/* and /api/ws/* on the assumption those handlers enforce their own authentication, but the MCP WebSocket handler never did, so the endpoint is reachable without credentials regardless of the configured auth mode (github, msal, or firebase). The third link is command injection (CWE-78, OS Command Injection): the WebSocket endpoint accepts a server_params query parameter holding base64-encoded JSON that is deserialized directly into a StdioServerParams object with no command allowlisting, so an attacker supplies an arbitrary command to execute. A demonstration payload of {"type":"StdioServerParams","command":"calc.exe","args":[],"env":{"pwned":"true"}} launches calc.exe on the host; any executable and arguments can be substituted.
The end-to-end flow: the operator's browsing agent is steered (via prompt injection embedded in the page or task) to a malicious URL; the page's JavaScript scans loopback ports, opens ws://localhost:8081/api/mcp/ws/?server_params=<base64> to the unauthenticated MCP socket, and the server decodes the parameters and spawns the attacker-chosen process as a stdio MCP server — full RCE in the context of the AutoGen Studio process.
Scope is narrow and the issue was never shipped: only development builds from the AutoGen repository main branch, between the MCP plugin landing and the hardening commit, contain the vulnerable /api/mcp/ws route. Published PyPI releases (current 0.4.2.2 at disclosure) do not include the MCP WebSocket route and are not affected. Microsoft states the chain was identified and remediated before any vulnerable code reached a PyPI release, and it was not exploited in the wild. The fix (commit b047730) introduces server-side parameter binding — a POST to /api/mcp/ws/connect stores parameters server-side under a UUID so they can no longer be injected through the URL — and tightens the middleware skip list so /api/mcp no longer bypasses authentication. AutoJack is documented here as a novel agentic-RCE TTP warranting detection guidance even absent in-the-wild exploitation.
MITRE ATT&CK techniques used in TL-2026-0862
Lateral Movement
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
stealth
Affected products and versions in AutoJack: Single-Page RCE Against Hosts Running AI Agents
- Microsoft — AutoGen Studio (autogenstudio)
Vulnerable versions: main-branch development builds between the MCP plugin landing commit and hardening commit b047730
Fixed in: main-branch commit b047730 and later; PyPI releases (0.4.2.2 and other published packages — the MCP WebSocket route was never shipped to PyPI)
Remediation for AutoJack: Single-Page RCE Against Hosts Running AI Agents
Patches
- AutoGen main-branch hardening commit b047730 (server-side parameter binding + tighter auth skip list)
Immediate actions
- Update AutoGen Studio development builds to main-branch commit b047730 or later, which adds server-side parameter binding for the MCP WebSocket and removes /api/mcp from the auth-middleware skip list
- Stay on published PyPI releases (>=0.4.2.2), which do not include the vulnerable /api/mcp/ws route
- Bind AutoGen Studio to loopback only and add host firewall rules blocking non-loopback access to port 8081
- Do not let a browsing/web-surfer agent and the developer share the same host as a privileged MCP-enabled AutoGen Studio instance
Workarounds
- Disable or remove the MCP WebSocket plugin / route on affected development builds
- Allowlist permitted MCP server executables instead of accepting arbitrary StdioServerParams.command
- Disable browsing/web-surfer agent capabilities when running a privileged AutoGen Studio instance
Longer-term hardening
- Place AutoGen Studio behind an authenticated reverse proxy that enforces authentication on ALL paths, including /api/mcp/* and /api/ws/*
- Run AutoGen Studio under a low-privilege account inside a sandboxed user profile (e.g., Windows Sandbox, Microsoft Dev Box)
- Separate the agent browsing identity from the developer identity (distinct Microsoft Entra Agent ID)
- Deploy untrusted-content-rendering agents only in isolated, disposable developer prototype environments
- Apply prompt-injection defenses (e.g., Azure AI Content Safety Prompt Shields) to content fed to browsing agents
Weaknesses (CWE) in AutoJack: Single-Page RCE Against Hosts Running AI Agents
CWE-1385, CWE-306, CWE-78
Timeline of AutoJack: Single-Page RCE Against Hosts Running AI Agents
- Precedent: CVE-2025-52882 (WebSocket authentication bypass in Claude Code IDE extensions) demonstrated unauthenticated localhost WebSocket RCE, establishing the missing-origin-validation + missing-auth pattern AutoJack reuses against AutoGen Studio's MCP socket.
- Precedent for the localhost-MCP attack class: CVE-2025-49596 (MCP Inspector drive-by localhost RCE) was disclosed, showing untrusted web content reaching a loopback MCP service — the same trust-boundary failure AutoJack later weaponizes via an AI browsing agent.
- Microsoft published companion research, 'When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps', framing the class of AI-app trust-boundary and configuration flaws that AutoJack exemplifies.
- Microsoft published Defender advanced hunting queries for AutoGen Studio child processes, MCP WebSocket connections carrying server_params, and browser-automation agents reaching non-corporate domains.
- Microsoft confirmed the issue was identified and remediated before any vulnerable code shipped to a PyPI release and was not exploited in the wild.
- Only main-branch development builds between the MCP plugin landing and commit b047730 are affected; published PyPI releases (current 0.4.2.2) never included the /api/mcp/ws route and are not affected.
- Remediation merged on the AutoGen main branch (commit b047730): server-side parameter binding via POST /api/mcp/ws/connect (UUID-keyed) and removal of /api/mcp from the auth-middleware skip list.
- Proof-of-concept demonstrated host process execution via a base64 StdioServerParams payload spawning calc.exe with env pwned=true through ws://localhost:8081/api/mcp/ws/.
- The three-link chain was documented: origin-allowlist bypass (CWE-1385), missing MCP authentication (CWE-306), and command injection via the server_params query parameter (CWE-78).
- Microsoft Defender Security Research publicly disclosed the AutoJack exploit chain against AutoGen Studio in the Microsoft Security Blog.
Sources cited for AutoJack: Single-Page RCE Against Hosts Running AI Agents
- AutoJack: Single-page RCE on a host running an AI agent
- When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps
- CWE-1385: Missing Origin Validation in WebSockets
- CWE-306: Missing Authentication for Critical Function
- CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
- CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions (analogous localhost WebSocket RCE)
- MCP Horror Stories: The Drive-By Localhost Breach (CVE-2025-49596, MCP Inspector localhost RCE)
- microsoft/autogen — A programming framework for agentic AI
- Confused deputy problem
Threats related to AutoJack: Single-Page RCE Against Hosts Running AI Agents
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
- AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector
- AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)
Detection coverage for TL-2026-0862
As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0862 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.