以下是该漏洞描述的中文翻译: atomic-agents-stack 在 1.1.0 版本之前,其 HTTP MCP 服务器注册表后端工厂接受明文 HTTP 协议,使得网络中间人攻击者能够篡改目录(catalog)响应。攻击者可以通过注入任意命令和参数值,这些值会被 MCPClientPool 作为本地子进程启动,从而在代理(agent)主机上实现任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dep0we | atomic-agents-stack | < 1.1.0 |
affected |
1.1.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dep0we | atomic-agents-stack | 0 ~ 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91989 | 7.5 HIGH | atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py |
| CVE-2026-91987 | 6.5 MEDIUM | atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model |
No comments yet