{"id":"GHSA-xhcr-cqfr-m3hv","summary":"atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)","details":"The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but content-unrestricted, and are later spawned as local stdio subprocesses by `MCPClientPool`. Over a cleartext `http://` catalog URL, a network man-in-the-middle can rewrite the catalog response to inject an arbitrary `command`/`args` and obtain code execution on the agent host, with no LLM involvement. The Policy MCP allowlist is not a default mitigation (`mcp_allow_fn` defaults to None), so absent an operator-authored allowlist every resolved spec connects.\n\n**Affected:** `mcp_registry/http.py`, all versions through 1.0.0. (The `https` path is sound: `httpx` defaults to `verify=True`, `follow_redirects=False`.)\n\n**Fix:** require `https` by default and gate `http://` behind a loud explicit opt-in. Defense-in-depth: allowlist the resolved command basename (or require confirmation) before any registry-sourced subprocess spawn. Document the consequence in spec/36.","aliases":["CVE-2026-91988"],"modified":"2026-09-16T03:56:06.204188287Z","published":"2026-08-17T21:49:55Z","database_specific":{"cwe_ids":["CWE-319","CWE-494"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-17T21:49:55Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/dep0we/atomic-agents-stack/security/advisories/GHSA-xhcr-cqfr-m3hv"},{"type":"PACKAGE","url":"https://github.com/dep0we/atomic-agents-stack"},{"type":"WEB","url":"https://github.com/dep0we/atomic-agents-stack/releases#release-v1.1.0"}],"affected":[{"package":{"name":"atomic-agents-stack","ecosystem":"PyPI","purl":"pkg:pypi/atomic-agents-stack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"versions":["1.0.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-xhcr-cqfr-m3hv/GHSA-xhcr-cqfr-m3hv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}