{"id":"GHSA-xhcr-cqfr-m3hv","title":"atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)","summary":"atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)","severity":"high","cwe":["CWE-319","CWE-494"],"vendor":"atomic-agents-stack","product":"atomic-agents-stack","ecosystem":"pip","affected":["atomic-agents-stack <= 1.0.0"],"patched":["atomic-agents-stack 1.1.0"],"published":"2026-08-17","updated":"2026-08-17","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xhcr-cqfr-m3hv","references":[{"url":"https://github.com/dep0we/atomic-agents-stack/security/advisories/GHSA-xhcr-cqfr-m3hv"},{"url":"https://github.com/dep0we/atomic-agents-stack/releases#release-v1.1.0"},{"url":"https://github.com/advisories/GHSA-xhcr-cqfr-m3hv"}],"tags":["ghsa","pip"],"ingestedAt":"2026-08-17T22:01:17.101Z","slug":"GHSA-xhcr-cqfr-m3hv","body":"## Overview\n\nThe HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but content-unrestricted, and are later spawned as local stdio subprocesses by `MCPClientPool`. Over a cleartext `http://` catalog URL, a network man-in-the-middle can rewrite the catalog response to inject an arbitrary `command`/`args` and obtain code execution on the agent host, with no LLM involvement. The Policy MCP allowlist is not a default mitigation (`mcp_allow_fn` defaults to None), so absent an operator-authored allowlist every resolved spec connects.\n\n**Affected:** `mcp_registry/http.py`, all versions through 1.0.0. (The `https` path is sound: `httpx` defaults to `verify=True`, `follow_redirects=False`.)\n\n**Fix:** require `https` by default and gate `http://` behind a loud explicit opt-in. Defense-in-depth: allowlist the resolved command basename (or require confirmation) before any registry-sourced subprocess spawn. Document the consequence in spec/36.\n\n## Affected packages\n\n- `atomic-agents-stack <= 1.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `atomic-agents-stack 1.1.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}