What happened
An authorization-ordering flaw in POST /api/user/plugins lets an authenticated low-privileged user omit the top-level MCP type so the stdio inspection check is skipped; the stored personal action then reaches the MCP stdio plugin factory and starts an attacker-selected operating-system process under the application service identity when the tool is invoked. CISA SSVC lists exploitation=poc. Requires personal plugins enabled and governance permitting MCP actions.
Why it matters
SimpleChat is Microsoft's secure document-grounded AI conversation/workspace app. The MCP stdio tool surface is the agent-command-execution boundary; bypassing its governance gate to start arbitrary OS processes under the service account can expose or modify secrets and data available to the service and disrupt the app — a low-privileged-to-service-account escalation on the AI platform.
Attack vector
Authenticated low-priv API call to POST /api/user/plugins omitting the MCP type to bypass the admin stdio check, then invoking the stored action to execute a chosen binary under the service identity.
Affected systems
Microsoft SimpleChat 0.261.003 and 0.261.027; fixed 0.261.031
Mitigation
Upgrade to SimpleChat 0.261.031; restrict personal-plugins/MCP-Actions governance settings in the interim.