AutoJack: A single page can RCE the host running your AI agent
AutoGen StudioAI agentvulnerabilityremote code executionAutoJackMCP WebSocketmodel context protocolsecurity research
Author: p_stuart82
Date: 6/20/2026
Article Summary:
Microsoft security researchers discovered a vulnerability in AutoGen Studio, an open-source prototyping user interface for AI agents, that allows untrusted web content to reach a local Model Context Protocol (MCP) WebSocket and spawn arbitrary processes on the host, dubbed "AutoJack".