AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + (TL-2026-0883), also tracked as AutoJack, is a critical-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Microsoft (Microsoft Research / AutoGen project) AutoGen Studio, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0883
- Threat ID
- TL-2026-0883
- Also known as
- AutoJack
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-06-19
- Last reviewed
- 2026-06-19
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, artificial intelligence, research
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
Malware and tooling: MultimodalWebSurfer, StdioServerParams stdio_client spawn
AutoJack is a three-vulnerability exploit chain in the MCP WebSocket surface of Microsoft AutoGen Studio. A malicious web page rendered by a local browsing agent opens a WebSocket to the localhost MCP endpoint, passes the localhost origin check, bypasses authentication, and injects an OS command via a base64-encoded server_params query parameter. In Microsoft's proof-of-concept, calc.exe launched on the developer's desktop within seconds, executed by the AutoGen Studio process itself with no user interaction beyond the agent visiting an attacker URL.
How AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + works
AutoJack is a confused-deputy / SSRF-style local RCE chain disclosed by Microsoft Defender Security Research on June 18, 2026, affecting the Model Context Protocol (MCP) WebSocket integration in Microsoft AutoGen Studio, the open-source prototyping UI for multi-agent AI systems from Microsoft Research. The attack abuses the trusted local position of a web-browsing AI agent to cross the localhost security boundary and achieve arbitrary command execution on the host.
The chain stitches together three distinct weaknesses. (1) Missing Origin Validation in WebSockets (CWE-1385): the MCP WebSocket handler only accepted an Origin of http://127.0.0.1 or http://localhost. This check is meant to block an ordinary remote browser pointed at a malicious site, but a headless browsing agent (e.g., MultimodalWebSurfer/Playwright) running on the same host IS localhost, so any page it renders inherits that localhost identity and passes the origin allowlist. (2) Missing Authentication for a Critical Function (CWE-306): the authentication middleware explicitly skipped /api/mcp/* paths on the assumption that the MCP handler would verify tokens itself. It never did, so the WebSocket accepted unauthenticated connections regardless of the configured auth mode. (3) OS Command Injection via server_params (CWE-78, with an underlying improper-input-validation root cause, CWE-20): the endpoint read a server_params query parameter, base64-decoded it, parsed it into a StdioServerParams object via json.loads, and passed the resulting command and args straight to stdio_client() with no executable allowlist. Any command (calc.exe, powershell.exe -enc <b64>, bash -c, certutil, mshta) could be launched under the developer's account.
Exploit flow: a developer runs AutoGen Studio on the default localhost:8081 with a browsing-capable agent. An attacker plants a malicious web page (or uses indirect/cross-domain prompt injection to steer the agent to one). When the agent renders the page, its JavaScript opens ws://localhost:8081/api/mcp/ws/?server_params=<base64_payload>. The origin check passes (the agent process is local), the auth middleware short-circuits /api/mcp/*, AutoGen Studio decodes the payload into StdioServerParams, and create_mcp_session spawns the attacker-supplied command. A sample payload was {"type":"StdioServerParams","command":"calc.exe","args":[],"env":{"pwned":"true"}}. Microsoft demonstrated it with malicious_web_server.py and web_summarizer_app.py (a 'Web Content Summarizer' agent); calc.exe popped on the desktop, launched by the AutoGen Studio process.
Exposure scope is narrow but real: the vulnerable MCP WebSocket route shipped only in the pre-release PyPI builds autogenstudio 0.4.3.dev1 and 0.4.3.dev2 (pulled only via pip --pre or explicit version pinning) and in development builds installed from source. The current stable PyPI release 0.4.2.2 does not contain the mcp.py route file or StdioServerParams references and is not affected. The chain was fixed upstream in commit b047730 (PR #7362) on the main branch (version 0.7.2): server_params is no longer accepted via the URL — a POST to /api/mcp/ws/connect now stores parameters server-side keyed to a one-time UUID session ID and the WebSocket refuses unknown IDs, and /api/mcp was removed from the authentication skip-list (only /api/ws and /api/maker remain exempt). No CVE or CVSS was assigned in the source reporting; Microsoft characterized this as a research disclosure with no observed in-the-wild exploitation. Microsoft recommends defense via Azure AI Content Safety Prompt Shields (indirect/XPIA prompt-injection detection), Microsoft Defender EDR (unexpected child-process spawning), Microsoft Entra Agent ID (isolating agent identity from developer privileges), and sandboxing agents in Microsoft Dev Box / Windows Sandbox / separate VMs running under low-privilege accounts.
MITRE ATT&CK techniques used in TL-2026-0883
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application
Credential Access
T1212 Exploitation for Credential Access
Persistence
T1505 Server Software Component
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Reconnaissance
Affected products and versions in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
- Microsoft (Microsoft Research / AutoGen project) — AutoGen Studio (autogenstudio)
Vulnerable versions: 0.4.3.dev1; 0.4.3.dev2; development/source builds with MCP WebSocket support prior to commit b047730
Fixed in: 0.7.2 (main branch, commit b047730 / PR #7362)
Remediation for AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
Patches
- Upstream AutoGen fix: commit b047730 (PR #7362), version 0.7.2 on the main branch — server-side server_params binding via /api/mcp/ws/connect with one-time UUID session IDs, and removal of /api/mcp from the auth skip-list.
Immediate actions
- Stop running AutoGen Studio with a browsing- or code-execution-capable agent on a developer workstation used for general web browsing.
- Verify the installed autogenstudio version is NOT 0.4.3.dev1 or 0.4.3.dev2; downgrade to stable 0.4.2.2 or upgrade source installs to main at/after commit b047730 (0.7.2).
- Block or firewall inbound connections to the local AutoGen Studio port (default 8081) from agent-controlled browser contexts.
Workarounds
- Do not load untrusted web pages with an agent while AutoGen Studio's MCP WebSocket is listening.
- Disable or do not configure MCP/StdioServerParams server spawning in development builds.
- Restrict outbound agent browsing to an allowlist of trusted domains.
Longer-term hardening
- Run AutoGen Studio and any web-browsing/tool-using agent inside an isolated container, VM, Windows Sandbox, or Microsoft Dev Box to contain RCE blast radius.
- Execute the AutoGen Studio process under a dedicated low-privilege account, never as developer/admin.
- Adopt Microsoft Entra Agent ID to separate agent identity and privileges from the developer's.
- Deploy indirect prompt-injection (XPIA) defenses such as Azure AI Content Safety Prompt Shields in front of browsing agents.
Weaknesses (CWE) in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
CWE-1385, CWE-306, CWE-78, CWE-20
Timeline of AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
- Microsoft published layered defensive guidance: Azure AI Content Safety Prompt Shields for indirect/XPIA prompt-injection, Microsoft Defender EDR for unexpected child-process spawning, Microsoft Entra Agent ID for agent identity isolation, and agent sandboxing via Dev Box / Windows Sandbox / low-privilege VMs.
- Microsoft confirmed the vulnerable MCP WebSocket route shipped only in pre-release builds autogenstudio 0.4.3.dev1 and 0.4.3.dev2 (and source/dev installs); the current stable PyPI release 0.4.2.2 lacks the mcp.py route and StdioServerParams references and is unaffected.
- Issue reported to and coordinated through the Microsoft Security Response Center (MSRC).
- Upstream fix landed in the AutoGen repository via commit b047730 (PR #7362): server-side server_params binding with one-time UUID session IDs and removal of /api/mcp from the auth skip-list (version 0.7.2 on main).
- Microsoft Defender Security Research publishes the AutoJack disclosure on the Microsoft Security Blog detailing the three-CWE MCP WebSocket exploit chain in AutoGen Studio.
- The Hacker News and CSO Online report on AutoJack, framing it as single-page RCE of the host running a web-enabled AI agent; no in-the-wild exploitation observed.
- Windows News and OffSeq Threat Radar publish secondary coverage summarizing the localhost RCE chain and affected pre-release builds.
- The Hacker News and CSO Online report on AutoJack, framing it as single-page RCE of the host running a web-enabled AI agent; no in-the-wild exploitation observed.
- Threat ingested into the Threadlinqs Intelligence pipeline as TL-2026-0883 from the Cyber Security News feed.
- Cyber Security News publishes a technical breakdown of the AutoJack chain (CWE-1385 + CWE-306 + CWE-78) and the calc.exe proof-of-concept.
Sources cited for AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
- AutoJack: How a single page can RCE the host running your AI agent
- AutoJack - Microsoft AutoGen Studio Exploit Chain
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
- Microsoft says web-enabled AI agents can trigger host-level RCE
- Microsoft Discloses AutoJack: A Malicious Webpage Can Hijack AutoGen Studio via Localhost RCE
- AutoGen fix PR #7362 / commit b047730 (server-side MCP param binding, auth skip-list tightening)
- AutoJack - Live Threat Intelligence (Threat Radar)
- CWE-1385: Missing Origin Validation in WebSockets
Threats related to AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +
- AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)
- AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector
- AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEV
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487)
- Node.js Windows Module Resolution Privilege Escalation via C:\node_modules Planting (CVE-2026-0775, CVE-2026-0776)
Detection coverage for TL-2026-0883
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0883 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.