SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-91988

HIGH · CVSS 8.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit atomic-agents-stack versions prior to 1.1.0 by leveraging cleartext HTTP connections in the MCP server-registry backend, enabling man-in-the-middle attacks. This can lead to arbitrary command injection and code execution on the agent host, posing a significant risk to system integrity. Organizations using this software should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91988
Severity
HIGH
CVSS
8.1
EPSS
0.25%

Original NVD Description

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.