Beveiligingsadvies

CVE-2026-91988

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 15:18:30
Laatst bijgewerkt 2026-09-15 15:50:03
Toegewezen door VulnCheck
CVSS-score 9.2
Status PUBLISHED

Beschrijving

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.