Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host. | |
| Title | atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:50:03.261Z
Reserved: 2026-09-15T11:10:41.354Z
Link: CVE-2026-91988
Updated: 2026-09-15T15:49:13.056Z
Status : Received
Published: 2026-09-15T16:17:57.450
Modified: 2026-09-15T16:17:57.450
Link: CVE-2026-91988
No data.
OpenCVE Enrichment
No data.