在版本 1.1.0 之前的 atomic-agents-stack 中,仪表盘 HTTP 服务器存在一个路径遍历(path traversal)漏洞,允许远程攻击者通过在请求路径中提供目录遍历序列(如 ),读取任意文件。攻击者可以在向 端点发送包含 段的请求时,绕过路径限制检查,从而访问 目录之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dep0we | atomic-agents-stack | 0 ~ 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91988 | 8.1 HIGH | atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
| CVE-2026-91987 | 6.5 MEDIUM | atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model |
No comments yet