What happened
Attacker hosts a malicious webpage containing JavaScript that opens a WebSocket to ws://localhost:8081/api/mcp/ws/?server_params= with base64-encoded StdioServerParams naming an arbitrary executable (e.g. calc.exe or a reverse shell). Any local AI browsing agent induced to visit this page — via planted link, prompt injection into browsed content, or social engineering — triggers process execution on the developer's host machine under their own account credentials, with no further interaction required.