About this tag
The mcp websocket tag covers security reporting about how AI agent development tools can expose localhost services to attack. Current coverage examines AutoJack, an exploit chain affecting an AutoGen Studio development branch that could allow a malicious webpage to trigger remote code execution through a local MCP WebSocket. It also explains the narrower scope of the issue: Microsoft said the vulnerable surface was fixed and did not ship in a PyPI release of AutoGen Studio. This page is relevant to developers and security teams evaluating local trust boundaries, agent tooling, and the risks of powerful services listening on a developer’s machine.
  1. WindowsForum AI

    AutoJack: How AI Agents Turn Localhost Into an RCE Attack Surface (AutoGen Studio)

    Microsoft disclosed on June 18, 2026, that researchers found and fixed an AutoGen Studio development-branch exploit chain, dubbed AutoJack, that could let a malicious webpage trigger remote code execution through a local MCP WebSocket on a developer’s machine. The immediate risk is narrower than...