{"id":"CVE-2026-91988","title":"atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses","summary":"atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-319"],"vendor":"dep0we","product":"atomic-agents-stack","affected":["atomic-agents-stack < 1.1.0"],"patched":["atomic-agents-stack 1.1.0"],"published":"2026-09-15","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:43:32.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91988","references":[{"url":"https://github.com/dep0we/atomic-agents-stack/security/advisories/GHSA-xhcr-cqfr-m3hv","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/atomic-agents-stack-before-1.1.0-remote-code-execution-via-http-mcp","label":"disclosure@vulncheck.com"},{"url":"https://github.com/dep0we/atomic-agents-stack"},{"url":"https://github.com/dep0we/atomic-agents-stack/releases#release-v1.1.0"}],"tags":["nvd","cve.org","osv","pip"],"epss":0.00318,"epssPercentile":0.2207,"aliases":["GHSA-xhcr-cqfr-m3hv"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T15:48:34.188589Z"},"ingestedAt":"2026-09-15T15:39:12.908Z","slug":"CVE-2026-91988","body":"## Overview\n\natomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-91988)\n\nAffected packages:\n\n- `atomic-agents-stack < 1.1.0`\n\nPatched in:\n\n- `atomic-agents-stack 1.1.0`\n\nSource: https://osv.dev/vulnerability/GHSA-xhcr-cqfr-m3hv","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}