PT-2026-92101 · Pypi · Atomic-Agents-Stack
CVE-2026-91987
·
Published
2026-08-17
·
Updated
2026-09-17
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
atomic-agents-stack versions prior to 1.1.0
Description
A cost-guardrail bypass exists in the
estimate batch cost() function within atomic agents/agent.py. The function uses PRICING.get(model, {}) to look up per-model output prices, which returns a value of 0.0 for any model not present in the hardcoded pricing table. Consequently, the check batch reservation() function skips the batch reservation process entirely when the reservation is less than or equal to zero. This allows attackers to use unknown model identifiers—such as self-hosted, Ollama, or vLLM models—to bypass daily cost caps and exceed budget limits during parallel batch operations, as the reservation is the primary defense against fan-out races where multiple parallel helpers read the same on-disk cost total simultaneously.Recommendations
Update atomic-agents-stack to version 1.1.0 or later.
As a temporary workaround, avoid using model identifiers not listed in the hardcoded pricing table when
cost guardrails and daily cap usd are enabled.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atomic-Agents-Stack