AutoJack: How a single page can RCE the host running your AI agent
2026-06-21T08:52:18Z•5094c4af8281ab3ebbaa5d4082a168897df3b6b4b03550b994672b3b6c8ebf68
AI agentAutoGen StudioAutoJackMCP WebSocketRCESSRF-likeagent-browsinglocal-servicelocalhostmissing-authenticationremote-code-executionunsafe-parameter-handlingweb-exploit
What happened
AutoJack is a chained exploit that shows a single malicious webpage can achieve remote code execution on the host running an AI browsing agent. The attack abuses the agent’s ability to load untrusted pages and access localhost services, leveraging missing authentication and unsafe parameter handling in AutoGen Studio’s MCP WebSocket to trigger arbitrary process execution on the host. The report highlights a class of risks when agents browse untrusted content and can reach local service endpoints (localhost), effectively turning agent browsing into a host RCE vector.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 5094c4af8281ab3ebbaa5d4082a168897df3b6b4b03550b994672b3b6c8ebf68
- Enrichment time
- 2026-06-21T08:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.