atomic-agents-stack
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting atomic-agents-stackpage 1 of 1
- CVE-2026-91987MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.1.02026-09-15
vulnerable: 1.0.0
atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers t…
- CVE-2026-91988HIGHCVSS 8.1EG 8.1✓ Fixed in 1.1.02026-09-15
vulnerable: 1.0.0
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument…
- CVE-2026-91989HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.02026-09-15
vulnerable: 1.0.0
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass pa…
Check whether atomic-agents-stack is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for atomic-agents-stack CVEs against the assets you own.
Start Free Scan →