logo

AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code

ID: a63f848a-0b36-514c-8851-a05a3b10d52c

STIX ID: report--a63f848a-0b36-514c-8851-a05a3b10d52c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Guru Baran

...
...

AutoJack is a three-vulnerability exploit chain against AutoGen Studio's MCP WebSocket that allows a malicious page — when rendered by a locally running browsing agent — to open an authenticated-appearing websocket to localhost and pass a base64-encoded server_params payload that is decoded and executed, resulting in arbitrary code execution on the developer's machine. The upstream project patched the issues (commit b047730, version 0.7.2), the PyPI release was confirmed not to include the vulnerable MCP surface, and the report outlines mitigations such as authentication enforcement, parameter server-side storage, executable allowlisting, and identity isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.