AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)
AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost (TL-2026-0904), also tracked as AutoJack, is a high-severity software vulnerability, first published 2026-06-22. It has no confirmed attribution, affects Microsoft AutoGen Studio (autogenstudio), maps to 13 MITRE ATT&CK techniques (T1021, T1027, T1059), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0904
- Threat ID
- TL-2026-0904
- Also known as
- AutoJack
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-06-22
- Last reviewed
- 2026-06-22
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, ai research, machine learning
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
Malware and tooling: AutoGen MultimodalWebSurfer / fetch_webpage_tool
AutoJack is a remote-code-execution exploit chain in Microsoft AutoGen Studio that lets a single attacker-controlled web page, rendered by a local browsing agent, reach the privileged MCP WebSocket control plane on localhost and spawn arbitrary host processes under the developer's account. Microsoft demonstrated a proof-of-concept launching Windows Calculator. The chain was fixed on the GitHub main branch at commit b047730 (PR #7362) before shipping in a stable PyPI release.
How AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost works
AutoJack is a three-flaw exploit chain in AutoGen Studio (the open-source prototyping UI for Microsoft's AutoGen multi-agent framework, 59,000+ GitHub stars) that converts a single malicious web page into full remote code execution on the host running the agent. The root cause is that AutoGen Studio's MCP (Model Context Protocol) WebSocket control plane treats 'localhost' as a trust boundary, but a browsing agent (MultimodalWebSurfer, fetch_webpage_tool, or other Playwright-backed surfers) executes on the same machine — so any JavaScript the agent loads from an attacker page inherits the localhost origin identity.
The chain links three distinct weaknesses. (1) Origin allowlist bypass (CWE-1385): the WebSocket validated Origin against an allowlist of ["http://127.0.0.1", "http://localhost"], a check designed to block remote browsers but trivially satisfied by an in-host agent browser, letting attacker JavaScript open ws://localhost:8081/api/mcp/ws/ connections that pass the origin check. (2) Authentication bypass (CWE-306): the authentication middleware short-circuited any path starting with /api/ws or /api/mcp ('if request.url.path.startswith("/api/ws") or request.url.path.startswith("/api/mcp"): return await call_next(request)'), delegating credential validation to the MCP handler, which never implemented it — leaving /api/mcp/ws/* unauthenticated under every auth mode (none, github, msal, firebase). (3) Command injection (CWE-78): the WebSocket handler read a base64-encoded 'server_params' query parameter, base64-decoded it, deserialized it into StdioServerParams, and passed it to stdio_client(), with no allowlist on the spawned executable — so a payload such as {"type":"StdioServerParams","command":"calc.exe","args":[],"env":{"pwned":"true"}} (or powershell.exe -enc / bash -c) was accepted as a 'MCP server' and executed.
End-to-end attack flow: a developer runs AutoGen Studio on localhost:8081 with a browsing agent; the agent is fed an attacker-controlled URL (via direct user submission, indirect/prompt injection, or a malicious comment); MultimodalWebSurfer navigates a headless browser to the attacker page; the page's JavaScript opens ws://localhost:8081/api/mcp/ws/?server_params=<base64payload>; the origin check passes (localhost-to-localhost) and the auth check is skipped; the payload is decoded and stdio_client() spawns the attacker-specified process under the developer's account. Microsoft's PoC ('malicious_web_server.py' serving the script payload, and a Flask-wrapped 'web_summarizer_app.py' Web Content Summarizer agent) showed calc.exe spawning on the developer desktop as a child of the AutoGen Studio Python process — not the browser, not the agent sandbox.
Remediation (commit b047730, PR #7362): the WebSocket handler no longer reads server_params from the URL. A new POST /api/mcp/ws/connect endpoint stores parameters server-side in a pending_session_params map keyed by a server-generated UUID; the WebSocket handler pops the entry by session ID and refuses unknown IDs with WebSocket close code 4004. The middleware skip-list was tightened to remove /api/mcp, so MCP routes now flow through normal authentication. Microsoft states the vulnerable MCP WebSocket surface was fixed before a stable PyPI release; the standard 'pip install autogenstudio' installs 0.4.2.2, which lacks the MCP WebSocket route (autogenstudio/web/routes/mcp.py) entirely. Reporting attributes the research to Shaked Ilan of Microsoft Defender Security Research with Microsoft Threat Intelligence, coordinated via MSRC; no in-the-wild exploitation was reported. The broader lesson — 'localhost is not a trust boundary' — applies to any agent framework that exposes a privileged local control plane reachable by in-host browsing agents.
MITRE ATT&CK techniques used in TL-2026-0904
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1204 User Execution
Command and Control
T1071 Application Layer Protocol
Collection
T1185 Browser Session Hijacking
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application
Credential Access
T1539 Steal Web Session Cookie
lateral-movement
Affected products and versions in AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
- Microsoft — AutoGen Studio (autogenstudio)
Vulnerable versions: GitHub main branch builds between the MCP plugin landing and commit b047730
Fixed in: main at commit b047730 (PR #7362) and later - Microsoft — AutoGen Studio (PyPI)
Fixed in: 0.4.2.2 (stable PyPI release does not include the MCP WebSocket route)
Remediation for AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
Patches
- AutoGen Studio commit b047730 (PR #7362): server-side pending_session_params keyed by UUID, POST /api/mcp/ws/connect, WebSocket close code 4004 for unknown session IDs, and removal of /api/mcp from the auth middleware skip-list.
Immediate actions
- Update AutoGen Studio builds from GitHub main to commit b047730 (PR #7362) or later; the WebSocket handler no longer accepts server_params from the URL.
- Verify installs: 'pip install autogenstudio' retrieves stable 0.4.2.2, which lacks the vulnerable MCP WebSocket surface entirely — confirm you are not running a pre-b047730 main-branch build.
- Bind AutoGen Studio to loopback only and add host firewall rules blocking non-loopback traffic to port 8081.
Workarounds
- Disable agent web-browsing tools (MultimodalWebSurfer / fetch_webpage_tool / Playwright surfers) on machines running AutoGen Studio.
- Place AutoGen Studio behind an authenticated reverse proxy enforcing auth on ALL paths including /api/mcp/*.
- Run browsing/code-execution agents in a separate container or VM from the AutoGen Studio control plane.
Longer-term hardening
- Never bind a control plane to localhost without independent authentication on the WebSocket handler itself — do not rely on Origin allowlists as a trust boundary.
- Separate the agent browsing identity from the developer identity using a different OS user, container, or VM.
- Treat every tool parameter reachable from model output (and any content a browsing agent loads) as attacker-controlled.
- Allowlist executable invocations for any MCP/stdio server launch; reject arbitrary command/args.
- Run AutoGen Studio strictly as an isolated developer prototype under a low-privilege account in a sandboxed profile or container.
Weaknesses (CWE) in AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
CWE-1385, CWE-306, CWE-78, CWE-346, CWE-77
Timeline of AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
- Microsoft demonstrates a proof-of-concept spawning calc.exe on the developer desktop via a Web Content Summarizer agent fed an attacker URL (malicious_web_server.py + web_summarizer_app.py).
- Fix lands on AutoGen main branch at commit b047730 (PR #7362): server-side pending_session_params keyed by UUID, POST /api/mcp/ws/connect, close code 4004, and /api/mcp removed from the auth skip-list.
- Microsoft Defender Security Research (Shaked Ilan) publishes the AutoJack blog detailing the AutoGen Studio MCP WebSocket RCE chain.
- Independent outlets (GBHackers, CyberSecurityNews, Penligent) republish technical analysis emphasizing 'localhost is not a trust boundary.'
- The Hacker News publishes detailed coverage of the three-flaw chain and the b047730 remediation.
- No in-the-wild exploitation reported; exposure limited to developers building AutoGen Studio from GitHub main during the pre-b047730 window.
- Threadlinqs Intelligence ingests the threat as TL-2026-0904 (HIGH, PATCHED) for detection-engineering coverage.
- BleepingComputer reports Microsoft fixed the AutoGen Studio flaw before any stable PyPI release; standard pip installs (0.4.2.2) unaffected.
Sources cited for AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
- AutoJack: How a single page can RCE the host running your AI agent
- Microsoft fixes AutoGen Studio flaw that enabled code execution
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
- AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack
- AutoJack - A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code
- AutoJack AI Agent RCE: Localhost Is Not a Trust Boundary
- AutoGen Studio MCP WebSocket hardening (PR #7362, commit b047730)
Threats related to AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
- AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)
- AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEV
Detection coverage for TL-2026-0904
As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0904 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.