AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution (opens in new tab)
TL;DR what: AutoJack chains three weaknesses in AutoGen Studio's MCP WebSocket so an attacker web page, loaded by a local AI browsing agent, runs arbitrary commands on the host. impact: Any page the agent opens can spawn a process under the account running AutoGen Studio with no credentials and no further user interaction. fix: The real fix is GitHub main at commit b047730 (PR #7362); no patched PyPI release exists yet, so stay on stable 0.4.2.2 or pull from source. who: Anyone who ran AutoGe...
Read the original article