ended6월 20일· 1 sources

AutoJack Weaponizes Local AI Agents Into Code Execution Vectors

AutoJack, 로컬 AI 에이전트를 통한 코드 실행 공격 발견

Why it matters

AutoJack exploits a critical vulnerability in AutoGen Studio's MCP WebSocket to turn local AI browsing agents into code execution conduits. Attackers can execute arbitrary commands on a developer's host system simply by serving a malicious web page to the agent—no credentials, authentication, or additional interaction required. This exploit chain reveals a concerning new attack surface in AI development frameworks, where untrusted web content can compromise the underlying system's integrity.

1
Sources
+0
24h
Growth
93d
Active
AutoJackAutoGen StudioCode executionWebSocketAgent vulnerability

Sources

Related Issues