Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Exposes AutoJack Exploit in AI Browsing Agents

Microsoft Exposes AutoJack Exploit in AI Browsing Agents

Posted on June 19, 2026 By CWS

Microsoft researchers have recently revealed a significant vulnerability, termed AutoJack, which allows an AI browsing agent to facilitate remote code execution. By directing the agent to access a malicious web page, attackers can exploit JavaScript to interact with a privileged local service on the host machine, thereby executing unauthorized processes.

Understanding the AutoJack Exploit

The AutoJack vulnerability is found within AutoGen Studio, an open-source prototype interface part of Microsoft Research’s AutoGen multi-agent framework. This flaw does not affect all users of the package, as it requires specific installation circumstances to be vulnerable. The stable release of AutoGen Studio, version 0.4.2.2, is unaffected due to the absence of a Model Context Protocol (MCP) route.

However, two pre-release versions, 0.4.3.dev1 and 0.4.3.dev2, do contain the vulnerable MCP WebSocket route. These versions allow unauthenticated command execution, posing a risk when installed. Despite this, the default installation method does not include pre-releases unless specifically requested, minimizing widespread exposure.

Mechanics of the Exploit Chain

The AutoJack exploit leverages three specific weaknesses within the MCP WebSocket. First, the WebSocket’s localhost trust setting is easily bypassed by a local AI agent, allowing it to inherit trusted status. Next, the authentication middleware fails to verify tokens, resulting in unauthenticated connections. Finally, the endpoint executes commands directly from the request parameter without verification, enabling arbitrary code execution.

These weaknesses combined allow a web page accessed by a local agent to execute attacker-specified commands under the AutoGen Studio’s user account. Microsoft emphasizes that this vulnerability was identified through research, with no known real-world exploitation reported.

Mitigation and Future Implications

To address this issue, Microsoft has collaborated with the maintainers to strengthen the main code branch, ensuring that commands are no longer read directly from URLs. Instead, server-side session IDs are used for parameter storage, and authentication routes are rigorously enforced. However, these fixes have yet to be included in a PyPI release.

For users who installed the pre-release versions, it is advised to update from the GitHub repository at or after commit b047730. As a precaution, users should avoid running AutoGen Studio alongside browsing or code-execution agents that interact with untrusted content on the same machine.

The AutoJack vulnerability highlights broader concerns within AI agent frameworks, particularly regarding localhost as a security boundary. Microsoft anticipates similar issues in other systems, advocating for enhanced authentication measures and restricted process execution to mitigate future risks.

The Hacker News Tags:agent security, AI frameworks, AI security, AI vulnerability, AutoGen Studio, AutoJack, code execution, Cybersecurity, GitHub, localhost issues, Microsoft, PyPI, Research, Software Security, WebSocket exploit

Post navigation

Previous Post: Gcore Enhances Ucom’s Election Broadcast Security
Next Post: Critical LiteSpeed cPanel Vulnerability Added to CISA List

Related Posts

N-central Hotfix 2 Released Amid Security Concerns N-central Hotfix 2 Released Amid Security Concerns The Hacker News
Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks The Hacker News
AI Assistants Exploited as Malware Command Channels AI Assistants Exploited as Malware Command Channels The Hacker News
New Phishing Kit Targeting US and EU Enterprises New Phishing Kit Targeting US and EU Enterprises The Hacker News
SolarWinds Fixes Major Flaws in Serv-U Software SolarWinds Fixes Major Flaws in Serv-U Software The Hacker News
You Didn’t Get Phished — You Onboarded the Attacker You Didn’t Get Phished — You Onboarded the Attacker The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark