Source · DiggingBeagle record
AutoJack: How a single page can RCE the host running your AI agent
Microsoft technical disclosure of AutoJack, a development-branch AutoGen Studio chain from hostile web content through a local MCP WebSocket to host process execution.
- Published
- Jun 18, 2026
- Accessed
- Sep 14, 2026
- Publisher
- Microsoft Defender Security Research Team
- Source type
- primary
- Version
- 2026-06-18
- Rights
- Public web source; citation and short excerpt only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Microsoft describes an origin check, an MCP authentication gap and attacker-controlled server parameters combining into host RCE.
Claim-level citations (3)
- supportsAutoJack crossed from hostile web content into a local MCP control plane: Microsoft reports that untrusted web content rendered by a browsing agent could reach AutoGen Studio's local MCP WebSocket and spawn arbitrary host processes.
AutoJack chain at a glance
- supportsAutoJack crossed from hostile web content into a local MCP control plane: The chain combined a localhost origin assumption, an MCP authentication gap and attacker-controlled server parameters that were passed to stdio execution.
Anatomy of the chain
- supportsAutoJack crossed from hostile web content into a local MCP control plane: Microsoft states that the affected MCP WebSocket surface was fixed in upstream development and was never included in a PyPI release.
Fixes and hardening measures
Cite this record
DiggingBeagle. “AutoJack: How a single page can RCE the host running your AI agent.” Published Jun 18, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/autojack-how-a-single-page-can-rce-the-host-running-your-ai-agent/
Citation guidance