AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector

AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns (TL-2026-0873), also tracked as AutoJack, is a high-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Microsoft AutoGen Studio (autogenstudio), maps to 16 MITRE ATT&CK techniques (T1036, T1059, T1071), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0873

Threat ID
TL-2026-0873
Also known as
AutoJack
Severity
HIGH
Status
MONITORING
Category
VULNERABILITY
First published
2026-06-19
Last reviewed
2026-06-19
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software development, ai/ml research
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

Malware and tooling: Web Content Summarizer (AutoGen Studio agent)

Microsoft Defender Security Research disclosed AutoJack, a three-bug exploit chain in AutoGen Studio's MCP WebSocket that lets a single malicious web page, when rendered by a local AI browsing agent, reach the agent's localhost control channel and spawn arbitrary commands on the host. The chain combines a localhost-trusting origin allowlist (CWE-1385), an authentication middleware that opts MCP paths out of auth (CWE-306), and a command endpoint that runs an executable taken straight from a URL parameter (CWE-78). Demonstrated as a proof of concept (calc.exe pop); no exploitation in the wild and no CVE assigned.

How AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns works

AutoJack is an exploit chain disclosed by Microsoft on June 18, 2026 that demonstrates how an AI browsing agent can be coerced into becoming the attacker's last-mile remote-code-execution delivery vehicle. The target is AutoGen Studio, the low-code UI for Microsoft Research's AutoGen multi-agent framework. AutoGen Studio runs a local web service (default http://localhost:8081) and, in affected development builds on the main branch, exposed a Model Context Protocol (MCP) WebSocket control channel under /api/mcp/ws/.

The attack chains three independent weaknesses. First (CWE-1385, Missing Origin Validation), the MCP WebSocket enforced an origin allowlist that trusted http://127.0.0.1 and http://localhost. That check is meant to stop an ordinary remote browser pointed at a malicious site, but an AutoGen browsing agent (MultimodalWebSurfer) runs a headless browser on the same host, so any page it loads inherits the localhost identity and satisfies the origin check. Second (CWE-306, Missing Authentication), the AuthMiddleware contained an early-return skip-list for WebSocket-style paths including /api/ws and /api/mcp, on the assumption that the MCP handler would verify tokens itself; the handler never implemented that follow-up check, so the socket accepted unauthenticated connections regardless of the configured authentication mode. Third (CWE-78, OS Command Injection), the WebSocket endpoint accepted a base64-encoded server_params query parameter, decoded it into a StdioServerParams object, and passed the resulting command and args directly to stdio_client(...) with no allowlist on which executable could launch.

The end-to-end flow: a developer runs AutoGen Studio with a browsing agent on localhost:8081; an attacker plants a malicious page on the internet (or injects a URL into the agent prompt); the agent's MultimodalWebSurfer navigates a headless browser to the attacker page; the page's JavaScript opens ws://localhost:8081/api/mcp/ws/?server_params=<base64>; AutoGen Studio decodes the base64 JSON into StdioServerParams and spawns the requested command (e.g., calc.exe or powershell.exe) under the developer's account. Microsoft's proof of concept used a 'Web Content Summarizer' agent that, when fed an attacker URL, pops calc.exe on the developer's desktop.

Microsoft reported the behavior to the Microsoft Security Response Center (MSRC); the maintainers hardened the upstream main branch in commit b047730 (PR #7362). The fix stops reading the command from the URL: parameters are now stored server-side behind a one-time session ID via a new POST /api/mcp/ws/connect route, unknown IDs are refused, and MCP routes now flow through the normal authentication path (the middleware no longer exempts /api/mcp). Microsoft states the vulnerable MCP WebSocket surface was never included in a PyPI release, so the current PyPI build (0.4.2.2, which does not include autogenstudio/web/routes/mcp.py) is not exposed to this specific chain. The originating hunt and The Hacker News reporting note the dev pre-releases 0.4.3.dev1 and 0.4.3.dev2 on PyPI and that neither build was yanked; sources differ on whether the vulnerable route reached a packaged pre-release, so source installs and dev builds tracking main during the affected window should be treated as the at-risk population. Microsoft emphasizes the broader lesson: when an agent on your machine can browse the open web and talk to privileged local services, localhost stops being a trust boundary; the pattern is broader than this single bug.

MITRE ATT&CK techniques used in TL-2026-0873

Defense Evasion

T1036 Masquerading; T1211 Exploitation for Stealth

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication

Command and Control

T1071 Application Layer Protocol; T1132 Data Encoding; T1571 Non-Standard Port

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1659 Content Injection

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities

Affected products and versions in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

  • Microsoft — AutoGen Studio (autogenstudio)
    Vulnerable versions: main-branch development builds including autogenstudio/web/routes/mcp.py (between MCP plugin landing and hardening); 0.4.3.dev1; 0.4.3.dev2
    Fixed in: builds at or after commit b047730 (PR #7362)
  • Microsoft — AutoGen Studio (PyPI stable)
    Fixed in: 0.4.2.2 (does not include the MCP WebSocket route; not exposed to this chain)

Remediation for AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

Patches

  • Apply upstream AutoGen Studio fix commit b047730 (PR #7362)

Immediate actions

  • Inventory hosts running AutoGen Studio from source or dev builds (0.4.3.dev1/0.4.3.dev2 or any main-branch checkout) that include autogenstudio/web/routes/mcp.py
  • Update to a build at or after upstream commit b047730 (PR #7362) where MCP parameters are bound server-side and MCP routes flow through normal auth
  • If immediate patching is not possible, do not run AutoGen Studio browsing agents (MultimodalWebSurfer) against untrusted URLs or untrusted prompt input
  • Bind the AutoGen Studio service to a restricted interface and firewall localhost:8081 from agent-driven headless browsers where feasible

Workarounds

  • Disable or remove the MCP WebSocket route (autogenstudio/web/routes/mcp.py) in affected source installs
  • Restrict the AutoGen Studio browsing agent from navigating to untrusted/non-corporate domains
  • Stay on the current stable PyPI release (0.4.2.2), which does not ship the vulnerable MCP route

Longer-term hardening

  • Treat localhost as an untrusted boundary on any host where an AI agent can both browse the open web and reach privileged local services
  • Require authentication and origin validation on all local agent control channels, including WebSocket/MCP endpoints
  • Allowlist which executables an agent control channel may launch; never pass user/URL-derived parameters directly to a process spawner
  • Run browsing agents in isolated sandboxes or containers with no access to host-local control services
  • Deploy EDR with behavioral detection for unexpected child processes of agent runtimes

Weaknesses (CWE) in AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

CWE-1385, CWE-306, CWE-78

Timeline of AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

  • Microsoft publishes advanced-hunting guidance to detect WebSocket connections to localhost:8081 carrying a server_params parameter and anomalous child processes of the AutoGen Studio runtime.
  • Microsoft demonstrates a proof of concept: a 'Web Content Summarizer' browsing agent fed an attacker URL pops calc.exe on the developer's desktop; no in-the-wild exploitation reported.
  • Upstream fix landed in commit b047730 (PR #7362): server-side parameter binding behind a one-time session ID, refusal of unknown IDs, and MCP routes flowing through normal authentication.
  • Behavior reported to the Microsoft Security Response Center (MSRC); maintainers hardened the upstream AutoGen Studio main branch prior/concurrent to disclosure.
  • Microsoft Defender Security Research (Shaked Ilan, with contributions from Microsoft Threat Intelligence) publishes the AutoJack disclosure detailing the AutoGen Studio MCP WebSocket exploit chain.
  • Sources note PyPI stable 0.4.2.2 does not ship autogenstudio/web/routes/mcp.py and is unaffected, while source/main-branch checkouts and dev pre-releases 0.4.3.dev1/0.4.3.dev2 (not yanked) constitute the at-risk population.
  • Defensive guidance issued: patch to commit b047730, isolate browsing agents from local control channels, and treat localhost as an untrusted boundary on agent-capable hosts.
  • Assessed HIGH severity, POC_PUBLIC exploitability; current PyPI stable 0.4.2.2 not exposed (does not ship the MCP route), source/dev-build population treated as at-risk.
  • Threadlinqs Intelligence opens tracking TL-2026-0873 on PoC-availability and developer-workstation / local-service-exposure risk; no CVE assigned and no CVSS published in sources.
  • The Hacker News and other outlets report the AutoJack chain, noting dev pre-releases 0.4.3.dev1/0.4.3.dev2 and that neither build was yanked.

Sources cited for AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

Threats related to AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns

Detection coverage for TL-2026-0873

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0873 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats