CVE-2026-91988
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-319
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- dep0we atomic-agents-stack
- dep0we atomic-agents-stack
Weakness type
Related vulnerabilities
- CVE-2025-47419 — Non-Secure Access
- CVE-2025-11492 — HTTP Configuration and Encryption in Transit
- CVE-2025-27720 — Pixmeo OsiriX MD Cleartext Transmission of Sensitive Information
- CVE-2026-24060 — Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information
- CVE-2025-54156 — Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
- CVE-2024-12378 — On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
- CVE-2025-0556 — Telerik Report Server Clear Text Transmission of Agent Commands
- CVE-2026-32309 — Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemes