Remote Code Execution in Atomic Agents Stack by Vendor Nuclear Alliance
CVE-2026-91988
9.2CRITICAL
What is CVE-2026-91988?
The Atomic Agents Stack prior to version 1.1.0 is susceptible to a serious vulnerability that allows for remote code execution. This issue arises from the acceptance of cleartext HTTP schemes in the HTTP MCP server-registry backend factory. By exploiting this vulnerability, network-based attackers can execute man-in-the-middle attacks to intercept and modify catalog responses. This allows attackers to inject arbitrary commands and arguments, which the MCPClientPool executes as local subprocesses on the agent host, potentially compromising the integrity and security of the system.
Affected Version(s)
atomic-agents-stack 0 < 1.1.0
atomic-agents-stack 1.1.0
