Microsoft Defender Security Research Team
aidefend-sf0014
AutoJack Localhost Agent Control-Plane RCE
- Autonomous Agents
- Tool Integrations & MCP
- System Compromise & RCE
Microsoft demonstrated that an AutoGen Studio main-branch development window allowed attacker web content rendered by a browsing agent to reach a localhost MCP WebSocket, bypass authentication, and supply server_params that spawned arbitrary host processes. The affected MCP route was fixed in commit b047730 before it appeared in any PyPI release.