---
id: CVE-2026-91987
title: >-
  atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the
  _estimate_batch_cost function that returns zero cost for unknown models not in
  the pricing table
summary: >-
  atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the
  _estimate_batch_cost function that returns zero cost for unknown models not in
  the pricing table. Attackers can configure deployments with unknown model
  identifiers…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: dep0we
product: atomic-agents-stack
affected:
  - atomic-agents-stack < 1.1.0
patched:
  - atomic-agents-stack 1.1.0
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:48:01.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91987'
references:
  - url: >-
      https://github.com/dep0we/atomic-agents-stack/security/advisories/GHSA-j659-8xh6-5pq5
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/atomic-agents-stack-before-1.1.0-cost-guardrail-bypass-via-unknown-model
    label: disclosure@vulncheck.com
  - url: 'https://github.com/dep0we/atomic-agents-stack'
  - url: 'https://github.com/dep0we/atomic-agents-stack/releases#release-v1.1.0'
tags:
  - nvd
  - cve.org
  - osv
  - pip
epss: 0.00476
epssPercentile: 0.38533
aliases:
  - GHSA-j659-8xh6-5pq5
ecosystem: pip
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T15:15:10.843975Z'
ingestedAt: '2026-09-15T15:39:12.909Z'
---

## Overview

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-91987)

Affected packages:

- `atomic-agents-stack < 1.1.0`

Patched in:

- `atomic-agents-stack 1.1.0`

Source: https://osv.dev/vulnerability/GHSA-j659-8xh6-5pq5
