Mark RadarMARK RADAR
EN
Event File AI Agentic AI

AutoJack Flaw in AutoGen Studio Lets Malicious Websites Run Local Programs

1 reports · First detected 2026-06-22 · Last active 2026-06-22

AutoGen Studio is a development tool in Microsoft’s AutoGen ecosystem for building and testing multi-agent workflows. If an agent can browse the web and connect to local MCP services, an interface designed to integrate tools can become an attack path from the web into the operating system. AutoJack therefore serves as a warning for AI agent security design.

A Microsoft research team recently disclosed AutoJack, saying the local MCP WebSocket interface in a development version of AutoGen Studio had an authentication design flaw. An attacker merely needed to lure an AI agent to a malicious website to potentially bypass authentication and execute arbitrary programs on the user’s computer. Maintainers have patched the issue in the main GitHub branch, but public information does not specify the exact disclosure or patch dates.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)