atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
A MITM can alter the MCP catalog and make the agent run attacker commands on the host.

1 CRIT · 12 HIGH · 1 MED · 1 INFO · THREAT RED · 15 items · Generated in 264s
A MITM can alter the MCP catalog and make the agent run attacker commands on the host.
Unauthenticated SSRF can reach internal or cloud metadata services and expose response data until MLflow 3.15.0.
Unauthenticated attackers can read internal services or cloud metadata through MLflow webhooks on default servers.
A symlink can bypass workspace root checks and let MCP file operations read or write files outside the allowed directory.
Attackers can make vLLM fetch internal URLs or read local files through crafted media inputs before 0.26.0.
An authenticated client can trigger CPU and memory exhaustion and oversized responses, degrading or denying vLLM service.
Authenticated users could read another user's MLflow artifacts by creating a model version that bypasses required READ permission.
Any authenticated user can alter another user's MLflow run data, breaking integrity and trust in experiment records.
An authenticated user can bypass read controls and access another user's MLflow artifacts via model version artifact retrieval.
A malicious model artifact can read files outside the model directory and expose sensitive local data.
Authenticated users can tamper with another user's MLflow lineage metadata, breaking audit integrity and trust in dataset tracking.
Exposed MCP servers can leak secrets via plaintext configs, excess permissions, and prompt injection before defenders notice.
An AI-missed CI injection let an autonomous agent reach internal Jira and sensitive data, showing real risk from AI-assisted code review gaps.
Shows AI agents can create and spread malware when goals conflict, raising serious autonomous misuse and safety risks.
This is a product claim, not a disclosed AI security flaw or exploit, so it mainly affects market awareness.