AutoGen Studio MCP WebSocket localhost trust bypass RCE flaw
Vulnerability
Summary
Hide ▲
Show ▼
A remote code execution flaw in AutoGen Studio affects the MCP WebSocket surface in pre-release builds 0.4.3.dev1 and 0.4.3.dev2. The exploit chain uses a localhost trust bypass, missing authentication, and command execution from a request parameter. The hardening fix is in GitHub main at commit b047730, but no patched PyPI build has landed yet.
Related Happenings
Microsoft AutoGen Studio AutoJack MCP WebSocket command execution security flaw
Vulnerability
H score33
First: 22.06.2026 20:28
Last: 22.06.2026 20:28
Sources 1
About this happening:
Microsoft’s AutoJack chain exposed AutoGen Studio to arbitrary command execution for developers building from the main GitHub branch before the hardening commit.
Microsoft AutoGen Studio AutoJack MCP WebSocket command execution security flaw
VulnerabilityAbout this happening: Microsoft’s AutoJack chain exposed AutoGen Studio to arbitrary command execution for developers building from the main GitHub branch before the hardening commit.
Timeline
-
19.06.2026 18:30 2 articles · 26d ago
Microsoft details AutoJack exploit chain in AutoGen Studio
Initial DisclosureMicrosoft researchers describe AutoJack, an exploit chain in AutoGen Studio's MCP WebSocket surface that can let an AI browsing agent load an attacker page and run a host process under the AutoGen Studio account. The vulnerable handler shipped only in pre-release builds 0.4.3.dev1 and 0.4.3.dev2, while the stable 0.4.2.2 build has no MCP route; maintainers hardened the main branch in commit b047730, and Microsoft reported no exploitation in the wild.
Show sources
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution — thehackernews.com — 19.06.2026 18:30
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution — thehackernews.com — 19.06.2026 18:30