ended6월 20일· 1 sources
AutoJack Weaponizes Local AI Agents Into Code Execution Vectors
AutoJack, 로컬 AI 에이전트를 통한 코드 실행 공격 발견
Why it matters
AutoJack exploits a critical vulnerability in AutoGen Studio's MCP WebSocket to turn local AI browsing agents into code execution conduits. Attackers can execute arbitrary commands on a developer's host system simply by serving a malicious web page to the agent—no credentials, authentication, or additional interaction required. This exploit chain reveals a concerning new attack surface in AI development frameworks, where untrusted web content can compromise the underlying system's integrity.
1
Sources
+0
24h
—
Growth
93d
Active
AutoJackAutoGen StudioCode executionWebSocketAgent vulnerability