AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector
AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns (TL-2026-0873), also tracked as AutoJack, is a high-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Microsoft AutoGen Studio (autogenstudio), maps to 16 MITRE ATT&CK techniques (T1036, T1059, T1071), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0873
- Threat ID
- TL-2026-0873
- Also known as
- AutoJack
- Severity
- HIGH
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- 2026-06-19
- Last reviewed
- 2026-06-19
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, ai/ml research
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
Malware and tooling: Web Content Summarizer (AutoGen Studio agent)
Microsoft Defender Security Research disclosed AutoJack, a three-bug exploit chain in AutoGen Studio's MCP WebSocket that lets a single malicious web page, when rendered by a local AI browsing agent, reach the agent's localhost control channel and spawn arbitrary commands on the host. The chain combines a localhost-trusting origin allowlist (CWE-1385), an authentication middleware that opts MCP paths out of auth (CWE-306), and a command endpoint that runs an executable taken straight from a URL parameter (CWE-78). Demonstrated as a proof of concept (calc.exe pop); no exploitation in the wild and no CVE assigned.
How AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns works
AutoJack is an exploit chain disclosed by Microsoft on June 18, 2026 that demonstrates how an AI browsing agent can be coerced into becoming the attacker's last-mile remote-code-execution delivery vehicle. The target is AutoGen Studio, the low-code UI for Microsoft Research's AutoGen multi-agent framework. AutoGen Studio runs a local web service (default http://localhost:8081) and, in affected development builds on the main branch, exposed a Model Context Protocol (MCP) WebSocket control channel under /api/mcp/ws/.
The attack chains three independent weaknesses. First (CWE-1385, Missing Origin Validation), the MCP WebSocket enforced an origin allowlist that trusted http://127.0.0.1 and http://localhost. That check is meant to stop an ordinary remote browser pointed at a malicious site, but an AutoGen browsing agent (MultimodalWebSurfer) runs a headless browser on the same host, so any page it loads inherits the localhost identity and satisfies the origin check. Second (CWE-306, Missing Authentication), the AuthMiddleware contained an early-return skip-list for WebSocket-style paths including /api/ws and /api/mcp, on the assumption that the MCP handler would verify tokens itself; the handler never implemented that follow-up check, so the socket accepted unauthenticated connections regardless of the configured authentication mode. Third (CWE-78, OS Command Injection), the WebSocket endpoint accepted a base64-encoded server_params query parameter, decoded it into a StdioServerParams object, and passed the resulting command and args directly to stdio_client(...) with no allowlist on which executable could launch.
The end-to-end flow: a developer runs AutoGen Studio with a browsing agent on localhost:8081; an attacker plants a malicious page on the internet (or injects a URL into the agent prompt); the agent's MultimodalWebSurfer navigates a headless browser to the attacker page; the page's JavaScript opens ws://localhost:8081/api/mcp/ws/?server_params=<base64>; AutoGen Studio decodes the base64 JSON into StdioServerParams and spawns the requested command (e.g., calc.exe or powershell.exe) under the developer's account. Microsoft's proof of concept used a 'Web Content Summarizer' agent that, when fed an attacker URL, pops calc.exe on the developer's desktop.
Microsoft reported the behavior to the Microsoft Security Response Center (MSRC); the maintainers hardened the upstream main branch in commit b047730 (PR #7362). The fix stops reading the command from the URL: parameters are now stored server-side behind a one-time session ID via a new POST /api/mcp/ws/connect route, unknown IDs are refused, and MCP routes now flow through the normal authentication path (the middleware no longer exempts /api/mcp). Microsoft states the vulnerable MCP WebSocket surface was never included in a PyPI release, so the current PyPI build (0.4.2.2, which does not include autogenstudio/web/routes/mcp.py) is not exposed to this specific chain. The originating hunt and The Hacker News reporting note the dev pre-releases 0.4.3.dev1 and 0.4.3.dev2 on PyPI and that neither build was yanked; sources differ on whether the vulnerable route reached a packaged pre-release, so source installs and dev builds tracking main during the affected window should be treated as the at-risk population. Microsoft emphasizes the broader lesson: when an agent on your machine can browse the open web and talk to privileged local services, localhost stops being a trust boundary; the pattern is broader than this single bug.
MITRE ATT&CK techniques used in TL-2026-0873
Defense Evasion
T1036 Masquerading; T1211 Exploitation for Stealth
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication
Command and Control
T1071 Application Layer Protocol; T1132 Data Encoding; T1571 Non-Standard Port
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1659 Content Injection
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities
Affected products and versions in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
- Microsoft — AutoGen Studio (autogenstudio)
Vulnerable versions: main-branch development builds including autogenstudio/web/routes/mcp.py (between MCP plugin landing and hardening); 0.4.3.dev1; 0.4.3.dev2
Fixed in: builds at or after commit b047730 (PR #7362) - Microsoft — AutoGen Studio (PyPI stable)
Fixed in: 0.4.2.2 (does not include the MCP WebSocket route; not exposed to this chain)
Remediation for AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
Patches
- Apply upstream AutoGen Studio fix commit b047730 (PR #7362)
Immediate actions
- Inventory hosts running AutoGen Studio from source or dev builds (0.4.3.dev1/0.4.3.dev2 or any main-branch checkout) that include autogenstudio/web/routes/mcp.py
- Update to a build at or after upstream commit b047730 (PR #7362) where MCP parameters are bound server-side and MCP routes flow through normal auth
- If immediate patching is not possible, do not run AutoGen Studio browsing agents (MultimodalWebSurfer) against untrusted URLs or untrusted prompt input
- Bind the AutoGen Studio service to a restricted interface and firewall localhost:8081 from agent-driven headless browsers where feasible
Workarounds
- Disable or remove the MCP WebSocket route (autogenstudio/web/routes/mcp.py) in affected source installs
- Restrict the AutoGen Studio browsing agent from navigating to untrusted/non-corporate domains
- Stay on the current stable PyPI release (0.4.2.2), which does not ship the vulnerable MCP route
Longer-term hardening
- Treat localhost as an untrusted boundary on any host where an AI agent can both browse the open web and reach privileged local services
- Require authentication and origin validation on all local agent control channels, including WebSocket/MCP endpoints
- Allowlist which executables an agent control channel may launch; never pass user/URL-derived parameters directly to a process spawner
- Run browsing agents in isolated sandboxes or containers with no access to host-local control services
- Deploy EDR with behavioral detection for unexpected child processes of agent runtimes
Weaknesses (CWE) in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
CWE-1385, CWE-306, CWE-78
Timeline of AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
- Microsoft publishes advanced-hunting guidance to detect WebSocket connections to localhost:8081 carrying a server_params parameter and anomalous child processes of the AutoGen Studio runtime.
- Microsoft demonstrates a proof of concept: a 'Web Content Summarizer' browsing agent fed an attacker URL pops calc.exe on the developer's desktop; no in-the-wild exploitation reported.
- Upstream fix landed in commit b047730 (PR #7362): server-side parameter binding behind a one-time session ID, refusal of unknown IDs, and MCP routes flowing through normal authentication.
- Behavior reported to the Microsoft Security Response Center (MSRC); maintainers hardened the upstream AutoGen Studio main branch prior/concurrent to disclosure.
- Microsoft Defender Security Research (Shaked Ilan, with contributions from Microsoft Threat Intelligence) publishes the AutoJack disclosure detailing the AutoGen Studio MCP WebSocket exploit chain.
- Sources note PyPI stable 0.4.2.2 does not ship autogenstudio/web/routes/mcp.py and is unaffected, while source/main-branch checkouts and dev pre-releases 0.4.3.dev1/0.4.3.dev2 (not yanked) constitute the at-risk population.
- Defensive guidance issued: patch to commit b047730, isolate browsing agents from local control channels, and treat localhost as an untrusted boundary on agent-capable hosts.
- Assessed HIGH severity, POC_PUBLIC exploitability; current PyPI stable 0.4.2.2 not exposed (does not ship the MCP route), source/dev-build population treated as at-risk.
- Threadlinqs Intelligence opens tracking TL-2026-0873 on PoC-availability and developer-workstation / local-service-exposure risk; no CVE assigned and no CVSS published in sources.
- The Hacker News and other outlets report the AutoJack chain, noting dev pre-releases 0.4.3.dev1/0.4.3.dev2 and that neither build was yanked.
Sources cited for AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
- AutoJack: How a single page can RCE the host running your AI agent
- AutoJack Attack Lets One Web Page Turn an AI Browsing Agent into an RCE Vector
- Microsoft says web-enabled AI agents can trigger host-level RCE
- Microsoft warns AI agents are being 'AutoJack'-ed to deliver RCE payloads by browsing untrusted websites
- Microsoft Discloses AutoJack: A Malicious Webpage Can Hijack AutoGen Studio via Localhost RCE
- CWE-1385: Missing Origin Validation in WebSockets
- CWE-306: Missing Authentication for Critical Function
- CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
- AutoGen Studio fix: bind MCP server_params server-side behind a one-time session ID (PR #7362)
- AutoGen Studio hardening commit b047730 (MCP routes flow through normal auth)
- Microsoft AutoGen — multi-agent framework repository
- AutoGen Studio on PyPI (stable 0.4.2.2)
Threats related to AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns
- AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
- AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)
- Laravel Framework CRLF Injection (CVE-2026-48019) — Outbound Email Header/Content Manipulation (CWE-93)
Detection coverage for TL-2026-0873
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0873 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.