漏洞描述(中文翻译): 在 1.1.0 版本之前存在成本护栏绕过漏洞。具体表现为: 函数对于不在定价表中的未知模型,其计算出的成本值为零。攻击者可以通过在并行批处理操作中部署使用未知模型标识符的配置,从而绕过每日成本上限,导致实际支出超出预算限制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dep0we | atomic-agents-stack | < 1.1.0 |
affected |
1.1.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dep0we | atomic-agents-stack | 0 ~ 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91988 | 8.1 HIGH | atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
| CVE-2026-91989 | 7.5 HIGH | atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py |
No comments yet