Impact
A path traversal flaw exists in the dashboard HTTP server of atomic‑agents‑stack. By crafting URL requests that include "../" segments, an attacker can bypass the intended containment checks on the DashboardHandler.do_GET endpoint and read files located outside the designated agents_root directory. This enables the remote acquisition of arbitrary files on the host, posing a significant breach of confidentiality.
Affected Systems
The vulnerability affects dep0we:atomic-agents-stack releases prior to version 1.1.0. Any user running an earlier iteration of the software is susceptible to this directory traversal flaw.
Risk and Exploitability
The CVSS score of 8.7 signals high severity, while an EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by sending anonymous HTTP requests to the dashboard service, leveraging the lack of proper path containment to retrieve sensitive configuration or system files, which could serve as a foothold for further compromise.
OpenCVE Enrichment