news.mlab.sh
Back to the feed
threat-intel

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

High
Image: The Hacker News
Summary

Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing agent to execute remote code execution by directing the agent to load a malicious web page. This occurs due to a lack of authentication and a bypassed localhost check within the MCP WebSocket, enabling an attacker to run commands on the host machine simply by opening a URL in the agent.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.