PT-2026-92101 · Pypi · Atomic-Agents-Stack

CVE-2026-91987

·

Published

2026-08-17

·

Updated

2026-09-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions atomic-agents-stack versions prior to 1.1.0
Description A cost-guardrail bypass exists in the estimate batch cost() function within atomic agents/agent.py. The function uses PRICING.get(model, {}) to look up per-model output prices, which returns a value of 0.0 for any model not present in the hardcoded pricing table. Consequently, the check batch reservation() function skips the batch reservation process entirely when the reservation is less than or equal to zero. This allows attackers to use unknown model identifiers—such as self-hosted, Ollama, or vLLM models—to bypass daily cost caps and exceed budget limits during parallel batch operations, as the reservation is the primary defense against fan-out races where multiple parallel helpers read the same on-disk cost total simultaneously.
Recommendations Update atomic-agents-stack to version 1.1.0 or later. As a temporary workaround, avoid using model identifiers not listed in the hardcoded pricing table when cost guardrails and daily cap usd are enabled.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91987
GHSA-J659-8XH6-5PQ5

Affected Products

Atomic-Agents-Stack