{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aatomic-agents-stackatomic-agents-stack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:atomic-agents-stack:atomic-agents-stack:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91989"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["atomic-agents-stack (\u003c 1.1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe atomic-agents-stack library, specifically versions prior to 1.1.0, contains a critical path traversal vulnerability within its dashboard HTTP server component. This vulnerability stems from improper input validation in the DashboardHandler.do_GET endpoint. Remote, unauthenticated attackers can leverage this flaw by supplying directory traversal sequences, such as \u0026quot;../\u0026quot;, within the HTTP request path. By doing so, the attacker can bypass existing path containment checks designed to restrict access to the agents_root directory, effectively granting them the ability to read arbitrary files from the underlying filesystem where the application is hosted. This vulnerability poses a significant risk to the confidentiality of sensitive configuration files, environment variables, or other stored data accessible to the service process. Defenders should prioritize updating to version 1.1.0 or later to mitigate this exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91989 allows an attacker to read any file on the server accessible to the atomic-agents-stack process. This can lead to full disclosure of application secrets, environment configurations, and other sensitive host data. The vulnerability is highly impactful due to the ease of exploitation, requiring only unauthenticated HTTP requests to the dashboard interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the atomic-agents-stack dependency to version 1.1.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing suspicious path segments like \u0026quot;../\u0026quot; or \u0026quot;%2e%2e/\u0026quot; targeting dashboard endpoints.\u003c/li\u003e\n\u003cli\u003eApply WAF rules to block HTTP requests containing directory traversal sequences directed at paths mapped to the dashboard component.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T17:44:37Z","date_published":"2026-09-15T17:44:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-atomic-agents-path-traversal/","summary":"The atomic-agents-stack library before version 1.1.0 is vulnerable to path traversal within its dashboard HTTP server, allowing remote attackers to read arbitrary files via crafted requests.","title":"Path Traversal Vulnerability in atomic-agents-stack","url":"https://feed.craftedsignal.io/briefs/2026-09-atomic-agents-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:atomic-Agents-Stack:atomic-Agents-Stack:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}