CVE-2026-91987

Source
https://cve.org/CVERecord?id=CVE-2026-91987
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91987.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91987
Aliases
Published
2026-09-15T15:18:29Z
Modified
2026-09-18T03:30:23Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model
Details

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91987.json"
}
References

Affected packages

Git / github.com/dep0we/atomic-agents-stack

Affected ranges

Type
GIT
Repo
https://github.com/dep0we/atomic-agents-stack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.1.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.1.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.9.0
v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91987.json"