GHSA-xhcr-cqfr-m3hvHigh▾ Twilightatomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The HTTP MCP server-registry backend factory (atomic_agents/mcp_registry/http.py, make_http_mcp_server_registry_backend_from_url) accepts both http and https schemes. Catalog entries carry command/args that are type-validated but content-unrestricted, and are later spawned as local stdio subprocesses by MCPClientPool. Over a cleartext http:// catalog URL, a network man-in-the-middle can rewrite the catalog response to inject an arbitrary command/args and obtain code execution on the agent host, with no LLM involvement. The Policy MCP allowlist is not a default mitigation (mcp_allow_fn defaults to None), so absent an operator-authored allowlist every resolved spec connects.
Affected: mcp_registry/http.py, all versions through 1.0.0. (The https path is sound: httpx defaults to verify=True, follow_redirects=False.)
Fix: require https by default and gate http:// behind a loud explicit opt-in. Defense-in-depth: allowlist the resolved command basename (or require confirmation) before any registry-sourced subprocess spawn. Document the consequence in spec/36.
atomic-agents-stack <= 1.0.0Upgrade to a patched release:
atomic-agents-stack 1.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91988High· 8.1atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses
CVE-2026-91987Medium· 6.5atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table
GHSA-j659-8xh6-5pq5Highatomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
CVE-2026-91989High· 7.5atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths
GHSA-rm43-82j9-r4mjHighatomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
CVE-2026-12259Medium· 5.3NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection