{"id":"GHSA-j659-8xh6-5pq5","title":"atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard","summary":"atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard","severity":"high","cwe":["CWE-770"],"vendor":"atomic-agents-stack","product":"atomic-agents-stack","ecosystem":"pip","affected":["atomic-agents-stack <= 1.0.0"],"patched":["atomic-agents-stack 1.1.0"],"published":"2026-08-17","updated":"2026-08-17","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-j659-8xh6-5pq5","references":[{"url":"https://github.com/dep0we/atomic-agents-stack/security/advisories/GHSA-j659-8xh6-5pq5"},{"url":"https://github.com/dep0we/atomic-agents-stack/releases#release-v1.1.0"},{"url":"https://github.com/advisories/GHSA-j659-8xh6-5pq5"}],"tags":["ghsa","pip"],"ingestedAt":"2026-08-17T22:01:17.065Z","slug":"GHSA-j659-8xh6-5pq5","body":"## Overview\n\n`_estimate_batch_cost` (`atomic_agents/agent.py`) looks up the per-model output price with `PRICING.get(model, {})`, returning 0.0 for any model not in the hardcoded pricing table. `_check_batch_reservation` then early-returns when the reservation is <= 0, skipping the batch reservation entirely. That reservation is the only defense against the documented fan-out race where every parallel helper/delegate reads the identical pre-batch on-disk cost total and each passes its individual check even though the collective spend overruns the configured cap.\n\n**Impact:** an operator running any model not in the pricing table (self-hosted/Ollama/vLLM, a new provider SKU) with `cost_guardrails` + `daily_cap_usd` set believes the cap protects them, but a single parallel batch can blow past the cap. The parallel-helper `model` argument can also be steered to an unknown id. The sibling `dream._estimate_dream_cost` does this correctly (`PRICING.get(model, _fallback_pricing())`), which makes this a clear defect.\n\n**Affected:** `agent.py` (`_estimate_batch_cost` / `_check_batch_reservation`), all versions through 1.0.0.\n\n**Fix:** use `PRICING.get(model, _costs._fallback_pricing())['output']` (mirror dream/calc_cost). Add a conformance test asserting an unknown-model batch reserves > 0 and that an over-cap unknown-model batch raises `CostGuardrailBlocked`.\n\n## Affected packages\n\n- `atomic-agents-stack <= 1.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `atomic-agents-stack 1.1.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}