CVE Tools

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

The Hacker NewsBy The Hacker News

PoC publicAutoGen StudioAutoGen

Our summary

Microsoft researchers describe the AutoJack exploit chain, which can let a single web page hijack an AI browsing agent into remote code execution on the host by targeting the MCP WebSocket handler in AutoGen Studio. Reported impact centers on pre-release versions 0.4.3.dev1 and 0.4.3.dev2 (while the standard PyPI install of 0.4.2.2 is stated to be unaffected) and is fixed in GitHub main at commit b047730. The broader risk pattern is tied to previous findings in Microsoft ecosystems, including CVE-2026-26030 and CVE-2026-25592, underscoring that “localhost” trust boundaries can fail when agents can both browse untrusted content and reach privileged local services.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store