THREAT OPS › Threat News › [GHSA] GHSA-xhcr-cqfr-m3hv (high) — atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
[GHSA] GHSA-xhcr-cqfr-m3hv (high) — atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
GHSA-xhcr-cqfr-m3hv Severity: high CVE: None
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but
Indicators of compromise
- http://`url
Original source: https://github.com/advisories/GHSA-xhcr-cqfr-m3hv