Vendor
The atomic-agents-stack library is vulnerable to remote code execution due to insecure handling of cleartext HTTP connections for MCP registry catalogs, allowing a Man-in-the-Middle attacker to inject malicious commands.