AutoJack Exploit Enables AI Agent Hijacking Through a Single Web Page
ID: f0621e55-cb45-57c2-b6af-4f31d79e613c
STIX ID: report--f0621e55-cb45-57c2-b6af-4f31d79e613c
Feed Name: Cyber Press
Threat Score
AutoJack is a chained exploit against AutoGen Studio's Model Context Protocol (MCP) WebSocket that lets an attacker-hosted web page (accessed by a local headless browsing agent) connect to localhost:8081, bypass origin and authentication checks, and deliver base64-encoded server_params that are executed as OS commands under the developer's account; Microsoft patched the issue in commit b047730 and the vulnerable MCP route is not present in the published PyPI package.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
