Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91988

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Sep 15, 2026
Vendor unknown

Description

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.

References