AutoJack Flaw in AutoGen Studio Lets Malicious Websites Run Local Programs
AutoGen Studio is a development tool in Microsoft’s AutoGen ecosystem for building and testing multi-agent workflows. If an agent can browse the web and connect to local MCP services, an interface designed to integrate tools can become an attack path from the web into the operating system. AutoJack therefore serves as a warning for AI agent security design.
A Microsoft research team recently disclosed AutoJack, saying the local MCP WebSocket interface in a development version of AutoGen Studio had an authentication design flaw. An attacker merely needed to lure an AI agent to a malicious website to potentially bypass authentication and execute arbitrary programs on the user’s computer. Maintainers have patched the issue in the main GitHub branch, but public information does not specify the exact disclosure or patch dates.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.