VulnSea

atomic-agents-stack vulnerabilities

CVEs whose affected-version data names the atomic-agents-stack package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-91987Medium· 6.5
6d ago

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers…

Sunlitdep0we · atomic-agents-stackEPSS 0.37%via NVD
CVE-2026-91989High· 7.5
6d ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-91988High· 8.1
6d ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

Twilightdep0we · atomic-agents-stackEPSS 0.25%via NVD
GHSA-xhcr-cqfr-m3hvHigh
1mo ago

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-j659-8xh6-5pq5High
1mo ago

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-rm43-82j9-r4mjHigh
1mo ago

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
atomic-agents-stack vulnerabilities (CVEs) · VulnSea