logo

Microsoft fixes AutoGen Studio flaw that enabled code execution

ID: 215944f8-9edc-5724-a22a-a0dd2bb6b656

STIX ID: report--215944f8-9edc-5724-a22a-a0dd2bb6b656

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Bill Toulas

...
...

AutoJack is a chained vulnerability in Microsoft AutoGen Studio's MCP WebSocket that could let a malicious webpage trick a local AI agent into launching arbitrary PowerShell, Bash commands, or executables by exploiting an origin bypass, excluded authentication routes, and base64-encoded server_params passed to process-launching code. Microsoft remediated the issue before any PyPI release, limiting exposure to developers who built from the repository during a brief window; users are advised to run AutoGen Studio only in isolated, low-privilege developer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.