External risk intelligence

Atomic Agents Stack Cleartext HTTP Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-91988

The vulnerability involves an MCP (Model Context Protocol) server-registry, which is typically used for internal agent-to-tool communication or local development environments. While network-reachable, it is not a standard internet-facing service or edge gateway by design, making public internet exposure possible but not a common or expected deployment pattern.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects systems using the atomic-agents-stack technology, allowing attackers to intercept and modify network communications. This could potentially lead to unauthorized command execution on the affected agent hosts. The main concern at this time is confirming the relevance and exposure of this technology within our environment.

  • Unprotected network traffic can be rewritten.
  • Could lead to code execution on agent hosts.
  • Confirm relevance and exposure; no immediate action.

Attack Path

How an attacker could exploit the issue

An attacker could intercept network traffic to a vulnerable agent, rewriting responses to inject malicious commands. These commands are then executed as local processes on the agent host.

  • Network exposure and unauthenticated access.
  • Rewritten catalog responses with command injection.
  • Local code execution on the agent.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to execute arbitrary code on the agent host when the HTTP MCP server-registry backend factory is used with cleartext HTTP. This could occur when network man-in-the-middle attackers intercept and rewrite catalog responses, leading to the injection of malicious commands.

  • Agent host code execution.
  • Man-in-the-middle rewriting catalog responses.
  • Compromise of agent host.

Operational Fix

Recommended remediation, mitigation, and detection steps

Attackers can exploit a cleartext HTTP vulnerability in the atomic-agents-stack to rewrite catalog responses, leading to code execution on the agent host. This issue likely impacts teams responsible for application development and infrastructure management, as well as any security or network teams monitoring internal agent communications. The first practical step is to identify all instances of the affected technology, assess their reachability and criticality, locate the accountable owners, and then plan remediation based on the identified risks.

  • Identify application and infrastructure owners.
  • Verify MCP server reachability and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the atomic-agents-stack software?

atomic-agents-stack is a framework that utilizes the Model Context Protocol (MCP) to manage communication between AI agents and their tools. It includes a server-registry backend factory that allows agents to discover and interact with various operational resources. This component is essential for orchestrating how agents execute tasks, acting as a bridge that enables automated workflows to connect with backend services during the agent's decision-making process.

How does CVE-2026-91988 cause code execution?

This vulnerability, classified as CWE-319 (Cleartext Transmission of Sensitive Information), occurs because the software accepts unencrypted HTTP traffic. Because the communication lacks encryption, an attacker can perform a man-in-the-middle attack to intercept and alter the data. By rewriting the registry responses, the attacker can inject malicious commands that the MCPClientPool then triggers as local subprocesses on the host machine, resulting in unauthorized code execution.

Does any network traffic trigger this vulnerability?

Only traffic directed to the HTTP MCP server-registry backend factory using cleartext HTTP schemes is susceptible. The vulnerability does not trigger if the communication is secured via encrypted channels or if the service is not utilizing the specifically affected registry backend factory. Internal communications that are isolated from network interception points do not present this specific trigger path.

How does Halo Surface Signal categorize this risk?

Halo Surface Signal identifies this as a possible risk with a score of 3. While the vulnerability is technically network-reachable, the MCP server-registry is generally intended for internal agent-to-tool communication or local development setups rather than public-facing services. This means that while internet-exposed instances are possible, they are not the typical or intended deployment pattern for this technology.

What is the first step for securing my environment?

You should begin by performing an inventory to locate all instances of atomic-agents-stack running in your infrastructure. Once identified, determine which instances are using the vulnerable HTTP MCP server-registry backend and evaluate their network reachability. Coordinate with the application and infrastructure owners to confirm the deployment context and prioritize these assets for updates as part of your standard risk management lifecycle.

References