Impact
The vulnerability lies in a cost‑guardrail bypass within the _estimate_batch_cost function of atomic‑agents‑stack; when an unknown model identifier is supplied, the function incorrectly returns a zero‑cost value. This allows attackers to configure deployments using arbitrary model names that are circumvent.
Affected Systems
The flaw affects dep0we atomic‑agents‑stack versions earlier than 1.1.0. Any instance deploying with a model identifier absent from the built‑in pricing table is susceptible.
Risk and Exploitability
The CVSS score of 7.1 suggests a moderate severity vulnerability. The EPSS score is below 1% and the flaw is not listed in the CISA KEV table, implying no confirmed exploits yet. Likely exploitation requires administrative or deployment‑configuration access, to supply the unknown model identifiers. If successfully abused and violate budget controls.
OpenCVE Enrichment