Microsoft disclosed AutoJack, an exploit chain in AutoGen Studio development code that allowed untrusted web content viewed by a local browsing agent to reach a localhost MCP WebSocket and launch arbitrary processes on the host. The attack combined three flaws: trust in localhost-based WebSocket origins, missing authentication on MCP WebSocket paths, and unsafe handling of attacker-controlled StdioServerParams supplied through the server_params query string, which was decoded into command execution.
Microsoft reported the issue to MSRC, and AutoGen maintainers hardened the upstream main branch in commit b047730 by moving parameter binding server-side and restoring authentication protections for MCP routes. Microsoft said the vulnerable MCP WebSocket surface was never shipped in a PyPI release, so users who installed AutoGen Studio from PyPI were not exposed to this specific chain, while warning that AI agent frameworks should not treat localhost as a trusted boundary when agents can browse untrusted content and interact with privileged local services.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
The AutoGen maintainers remediated the issue in the upstream main branch in commit b047730 by moving parameter binding server-side and restoring or tightening authentication coverage for MCP routes. The vulnerable MCP WebSocket surface had not been shipped in a PyPI release, so PyPI users were not exposed to this specific exploit chain.
After identifying the exploit chain, Microsoft reported the AutoJack issue to the Microsoft Security Response Center. This disclosure initiated remediation of the vulnerable AutoGen Studio development code.
Microsoft security researchers discovered an exploit chain they named AutoJack in AutoGen Studio development code that could let untrusted web content rendered by a local browsing agent reach a localhost MCP WebSocket and spawn arbitrary processes on the host. The chain relied on localhost-based WebSocket origin trust, missing authentication on MCP WebSocket paths, and unsafe execution of attacker-controlled StdioServerParams.
Microsoft researchers said the AutoJack issue affected AutoGen Studio pre-release PyPI builds 0.4.3.dev1 and 0.4.3.dev2, while stable release 0.4.2.2 was not affected because it lacked the MCP route. They also said the hardening in commit b047730 had not yet been released to PyPI at the time of reporting.
Microsoft publicly disclosed the AutoJack exploit chain and its security implications in a Microsoft Security Blog post. The disclosure also highlighted the broader lesson that localhost is not a trustworthy boundary when AI agents can browse untrusted content and interact with privileged local services.
In commit b047730, the AutoGen project deprecated FunctionTool in AutoGen Studio after identifying that FunctionTool instantiation used exec() on user-provided source code, including exposure through the /api/validate/ endpoint. The update removed FunctionTool creation and editing paths from the UI, added warnings recommending MCP Workbenches, and kept only limited compatibility for existing configurations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.