CVE-2026-91988: DEP0WE Atomic-Agents-Stack

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.

Affected products

  • DEP0WE Atomic-Agents-Stack: before 1.1.0 (fixed in 1.1.0)

Published 2026-09-15. Last modified 2026-09-24.