GHSA-wr36-693x-8mgcCriticalCVSS 8.1

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.

🔗 References (4)