PoC public AutoGen Studio rce AutoGen Microsoft auth-bypass
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
CVE Tools coverage
Microsoft researchers describe the AutoJack exploit chain, which can let a single web page hijack an AI browsing agent into remote code execution on the host by targeting the MCP WebSocket handler in AutoGen Studio. Reported impact centers on pre-release versions 0.4.3.dev1 and 0.4.3.dev2 (while the standard PyPI install of 0.4.2.2 is stated to be unaffected) and is fixed in GitHub main at commit b047730. The broader risk pattern is tied to previous findings in Microsoft ecosystems, including CVE-2026-26030 and CVE-2026-25592, underscoring that “localhost” trust boundaries can fail when agents can both browse untrusted content and reach privileged local services.