Description
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.
Published: 2026-09-15
Score: 8.7 High
EPSS: 1.3% Low
KEV: No
Impact: Remote File Disclosure
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw exists in the dashboard HTTP server of atomic‑agents‑stack. By crafting URL requests that include "../" segments, an attacker can bypass the intended containment checks on the DashboardHandler.do_GET endpoint and read files located outside the designated agents_root directory. This enables the remote acquisition of arbitrary files on the host, posing a significant breach of confidentiality.

Affected Systems

The vulnerability affects dep0we:atomic-agents-stack releases prior to version 1.1.0. Any user running an earlier iteration of the software is susceptible to this directory traversal flaw.

Risk and Exploitability

The CVSS score of 8.7 signals high severity, while an EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by sending anonymous HTTP requests to the dashboard service, leveraging the lack of proper path containment to retrieve sensitive configuration or system files, which could serve as a foothold for further compromise.

Generated by OpenCVE AI on September 20, 2026 at 16:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update atomic‑agents‑stack to version 1.1.0 or newer
  • Configure firewall or reverse proxy rules to limit dashboard access to trusted hosts or networks
  • If the dashboard endpoint is not required, disable or remove it to eliminate the exposure

Generated by OpenCVE AI on September 20, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dep0we
Dep0we atomic-agents-stack
Vendors & Products Dep0we
Dep0we atomic-agents-stack
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.
Title atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dep0we Atomic-agents-stack
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:27:51.603Z

Reserved: 2026-09-15T11:11:13.311Z

Link: CVE-2026-91989

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:33.462Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:58.010

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-91989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')