AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE

AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + (TL-2026-0883), also tracked as AutoJack, is a critical-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Microsoft (Microsoft Research / AutoGen project) AutoGen Studio, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0883

Threat ID
TL-2026-0883
Also known as
AutoJack
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
2026-06-19
Last reviewed
2026-06-19
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software development, artificial intelligence, research
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

Malware and tooling: MultimodalWebSurfer, StdioServerParams stdio_client spawn

AutoJack is a three-vulnerability exploit chain in the MCP WebSocket surface of Microsoft AutoGen Studio. A malicious web page rendered by a local browsing agent opens a WebSocket to the localhost MCP endpoint, passes the localhost origin check, bypasses authentication, and injects an OS command via a base64-encoded server_params query parameter. In Microsoft's proof-of-concept, calc.exe launched on the developer's desktop within seconds, executed by the AutoGen Studio process itself with no user interaction beyond the agent visiting an attacker URL.

How AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + works

AutoJack is a confused-deputy / SSRF-style local RCE chain disclosed by Microsoft Defender Security Research on June 18, 2026, affecting the Model Context Protocol (MCP) WebSocket integration in Microsoft AutoGen Studio, the open-source prototyping UI for multi-agent AI systems from Microsoft Research. The attack abuses the trusted local position of a web-browsing AI agent to cross the localhost security boundary and achieve arbitrary command execution on the host.

The chain stitches together three distinct weaknesses. (1) Missing Origin Validation in WebSockets (CWE-1385): the MCP WebSocket handler only accepted an Origin of http://127.0.0.1 or http://localhost. This check is meant to block an ordinary remote browser pointed at a malicious site, but a headless browsing agent (e.g., MultimodalWebSurfer/Playwright) running on the same host IS localhost, so any page it renders inherits that localhost identity and passes the origin allowlist. (2) Missing Authentication for a Critical Function (CWE-306): the authentication middleware explicitly skipped /api/mcp/* paths on the assumption that the MCP handler would verify tokens itself. It never did, so the WebSocket accepted unauthenticated connections regardless of the configured auth mode. (3) OS Command Injection via server_params (CWE-78, with an underlying improper-input-validation root cause, CWE-20): the endpoint read a server_params query parameter, base64-decoded it, parsed it into a StdioServerParams object via json.loads, and passed the resulting command and args straight to stdio_client() with no executable allowlist. Any command (calc.exe, powershell.exe -enc <b64>, bash -c, certutil, mshta) could be launched under the developer's account.

Exploit flow: a developer runs AutoGen Studio on the default localhost:8081 with a browsing-capable agent. An attacker plants a malicious web page (or uses indirect/cross-domain prompt injection to steer the agent to one). When the agent renders the page, its JavaScript opens ws://localhost:8081/api/mcp/ws/?server_params=<base64_payload>. The origin check passes (the agent process is local), the auth middleware short-circuits /api/mcp/*, AutoGen Studio decodes the payload into StdioServerParams, and create_mcp_session spawns the attacker-supplied command. A sample payload was {"type":"StdioServerParams","command":"calc.exe","args":[],"env":{"pwned":"true"}}. Microsoft demonstrated it with malicious_web_server.py and web_summarizer_app.py (a 'Web Content Summarizer' agent); calc.exe popped on the desktop, launched by the AutoGen Studio process.

Exposure scope is narrow but real: the vulnerable MCP WebSocket route shipped only in the pre-release PyPI builds autogenstudio 0.4.3.dev1 and 0.4.3.dev2 (pulled only via pip --pre or explicit version pinning) and in development builds installed from source. The current stable PyPI release 0.4.2.2 does not contain the mcp.py route file or StdioServerParams references and is not affected. The chain was fixed upstream in commit b047730 (PR #7362) on the main branch (version 0.7.2): server_params is no longer accepted via the URL — a POST to /api/mcp/ws/connect now stores parameters server-side keyed to a one-time UUID session ID and the WebSocket refuses unknown IDs, and /api/mcp was removed from the authentication skip-list (only /api/ws and /api/maker remain exempt). No CVE or CVSS was assigned in the source reporting; Microsoft characterized this as a research disclosure with no observed in-the-wild exploitation. Microsoft recommends defense via Azure AI Content Safety Prompt Shields (indirect/XPIA prompt-injection detection), Microsoft Defender EDR (unexpected child-process spawning), Microsoft Entra Agent ID (isolating agent identity from developer privileges), and sandboxing agents in Microsoft Dev Box / Windows Sandbox / separate VMs running under low-privilege accounts.

MITRE ATT&CK techniques used in TL-2026-0883

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1559 Inter-Process Communication

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application

Credential Access

T1212 Exploitation for Credential Access

Persistence

T1505 Server Software Component

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

  • Microsoft (Microsoft Research / AutoGen project) — AutoGen Studio (autogenstudio)
    Vulnerable versions: 0.4.3.dev1; 0.4.3.dev2; development/source builds with MCP WebSocket support prior to commit b047730
    Fixed in: 0.7.2 (main branch, commit b047730 / PR #7362)

Remediation for AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

Patches

  • Upstream AutoGen fix: commit b047730 (PR #7362), version 0.7.2 on the main branch — server-side server_params binding via /api/mcp/ws/connect with one-time UUID session IDs, and removal of /api/mcp from the auth skip-list.

Immediate actions

  • Stop running AutoGen Studio with a browsing- or code-execution-capable agent on a developer workstation used for general web browsing.
  • Verify the installed autogenstudio version is NOT 0.4.3.dev1 or 0.4.3.dev2; downgrade to stable 0.4.2.2 or upgrade source installs to main at/after commit b047730 (0.7.2).
  • Block or firewall inbound connections to the local AutoGen Studio port (default 8081) from agent-controlled browser contexts.

Workarounds

  • Do not load untrusted web pages with an agent while AutoGen Studio's MCP WebSocket is listening.
  • Disable or do not configure MCP/StdioServerParams server spawning in development builds.
  • Restrict outbound agent browsing to an allowlist of trusted domains.

Longer-term hardening

  • Run AutoGen Studio and any web-browsing/tool-using agent inside an isolated container, VM, Windows Sandbox, or Microsoft Dev Box to contain RCE blast radius.
  • Execute the AutoGen Studio process under a dedicated low-privilege account, never as developer/admin.
  • Adopt Microsoft Entra Agent ID to separate agent identity and privileges from the developer's.
  • Deploy indirect prompt-injection (XPIA) defenses such as Azure AI Content Safety Prompt Shields in front of browsing agents.

Weaknesses (CWE) in AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

CWE-1385, CWE-306, CWE-78, CWE-20

Timeline of AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

  • Microsoft published layered defensive guidance: Azure AI Content Safety Prompt Shields for indirect/XPIA prompt-injection, Microsoft Defender EDR for unexpected child-process spawning, Microsoft Entra Agent ID for agent identity isolation, and agent sandboxing via Dev Box / Windows Sandbox / low-privilege VMs.
  • Microsoft confirmed the vulnerable MCP WebSocket route shipped only in pre-release builds autogenstudio 0.4.3.dev1 and 0.4.3.dev2 (and source/dev installs); the current stable PyPI release 0.4.2.2 lacks the mcp.py route and StdioServerParams references and is unaffected.
  • Issue reported to and coordinated through the Microsoft Security Response Center (MSRC).
  • Upstream fix landed in the AutoGen repository via commit b047730 (PR #7362): server-side server_params binding with one-time UUID session IDs and removal of /api/mcp from the auth skip-list (version 0.7.2 on main).
  • Microsoft Defender Security Research publishes the AutoJack disclosure on the Microsoft Security Blog detailing the three-CWE MCP WebSocket exploit chain in AutoGen Studio.
  • The Hacker News and CSO Online report on AutoJack, framing it as single-page RCE of the host running a web-enabled AI agent; no in-the-wild exploitation observed.
  • Windows News and OffSeq Threat Radar publish secondary coverage summarizing the localhost RCE chain and affected pre-release builds.
  • The Hacker News and CSO Online report on AutoJack, framing it as single-page RCE of the host running a web-enabled AI agent; no in-the-wild exploitation observed.
  • Threat ingested into the Threadlinqs Intelligence pipeline as TL-2026-0883 from the Cyber Security News feed.
  • Cyber Security News publishes a technical breakdown of the AutoJack chain (CWE-1385 + CWE-306 + CWE-78) and the calc.exe proof-of-concept.

Sources cited for AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

Threats related to AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 +

Detection coverage for TL-2026-0883

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0883 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats