Vendor
high
advisory
Arbitrary Code Execution in atomic-agents-stack via MCP Registry Injection
2 TTPs 1 CVEThe atomic-agents-stack library before 1.1.0 allows man-in-the-middle attackers to inject malicious subprocess commands by exploiting cleartext HTTP communication in the MCP server-registry backend.
atomic-agents-stack
2t
1c
high
advisory
Remote Code Execution in atomic-agents-stack via Insecure MCP Registry
2 TTPsThe atomic-agents-stack library is vulnerable to remote code execution due to insecure handling of cleartext HTTP connections for MCP registry catalogs, allowing a Man-in-the-Middle attacker to inject malicious commands.
atomic-agents-stack
2t