THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xhcr-cqfr-m3hv (high) — atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

[GHSA] GHSA-xhcr-cqfr-m3hv (high) — atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

highgithub_advisoriesPublished 2026-08-17

GHSA-xhcr-cqfr-m3hv Severity: high CVE: None

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xhcr-cqfr-m3hv