Microsoft Security Blog • 7w
AutoJack: Host-Level RCE via AutoGen Studio AI Agents
Microsoft researchers identified "AutoJack," a critical exploit chain in AutoGen Studio's Model Context Protocol (MCP) WebSocket implementation. The attack allows a single malicious webpage to trigger host-level Remote Code Execution (RCE) by exploiting origin confusion and an authentication bypass in MCP paths. Specifically, unvalidated server_params passed via URL enable arbitrary command injection into process-spawning mechanisms like Bash or PowerShell. While patched in source builds, the vulnerability highlights a systemic risk in agentic frameworks that combine autonomous web browsing with privileged access to localhost services, effectively neutralizing traditional local security boundaries.
Links:Microsoft Security Blog, csoonline.com, feeds.feedburner.com, bulwarkblack.com, simplysecuregroup.com, Cybersecurity News, App, Inspectcybersecurity, Networkustad, Flexsin, gbhackers.com, cybersecurity.pk, Webdeveloper, Aiweekly, Letsdatascience, Daily, Cyberpress, bleepingcomputer.com, techjacksolutions.com, threat-modeling.com, Techgig, Medium, Reddit, Techradar, Github, Deepinspect, Tempmail, Stealthnet, Arxiv •