Back Redpacketsecurity CVE Alert: CVE-2026-91988 – dep0we – atomic-agents
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.
This is a high-consequence remote-code-execution weakness requiring urgent remediation, although current intelligence does not indicate active exploitation.
A successful attack could give an unauthenticated network attacker control of an agent host, enabling theft of secrets, manipulation of automated workflows, persistence, or disruption of services. The total technical impact is serious, but exploitation depends on a specific network interception or response-manipulation opportunity rather than being broadly opportunistic.
### Most likely attack path
An attacker positioned on the relevant network path intercepts or alters cleartext registry responses; no prior privileges or end-user action are required. The agent then processes attacker-controlled tool definitions and launches local commands, with scope assessed as unchanged, limiting direct impact on separately managed systems but allowing follow-on access using the host’s credentials and network reach.
### Who is most exposed
Prioritise organisations running agentic AI workflows with HTTP-based MCP registries, especially cloud-hosted agents, developer automation, CI/CD workers, and systems that can reach untrusted or shared networks.
Alert on agent subprocess creation that is unusual for the registered tool or workflow.
Capture and review registry responses, command arguments, and parent-child process relationships.
Identify cleartext HTTP registry endpoints in configuration, environment variables, and deployment manifests.
Hunt for unexpected outbound connections or newly introduced MCP tools.
Review host telemetry for credential access, persistence, or lateral movement after agent execution.
### Mitigation and prioritisation
Upgrade to the vendor-fixed release as soon as practical; treat as an urgent change.
Disable HTTP registry use and enforce authenticated HTTPS with certificate validation.
Restrict registry egress and place agent hosts in tightly segmented networks.
Run agents with least privilege, isolated credentials, and minimal subprocess capability.
KEV, EPSS, and PoC status are not supplied; obtain them to refine prioritisation.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
