{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/atomic-agents-stack-1.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["atomic-agents-stack (1.0.0)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","web-application","arbitrary-file-read"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe atomic-agents-stack dashboard HTTP server, specifically within the \u003ccode\u003eatomic_agents/dashboard/serve.py\u003c/code\u003e module, contains a path traversal vulnerability impacting all versions through 1.0.0. The vulnerability exists because the \u003ccode\u003eDashboardHandler.do_GET\u003c/code\u003e method constructs file paths based on incoming HTTP request URIs without performing containment checks or canonicalizing path segments. By including directory traversal sequences (such as \u003ccode\u003e../\u003c/code\u003e) in a request path, an attacker can bypass the intended \u003ccode\u003eagents_root\u003c/code\u003e directory to access sensitive files on the host filesystem.\u003c/p\u003e\n\u003cp\u003eWhile the server defaults to binding to the loopback interface, operators often utilize the \u003ccode\u003e--host\u003c/code\u003e flag to bind to other interfaces, potentially exposing the vulnerability to local area networks. Furthermore, even if bound to loopback, the interface remains susceptible to exploitation via DNS rebinding attacks originating from a victim's browser or server-side request forgery (SSRF) from other services running on the same host. This vulnerability allows for unauthorized file exfiltration and could facilitate further exploitation by exposing application configuration, secrets, or system files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary file read access on the host system. This could lead to the exposure of sensitive configuration files, environment variables, or other stored data, depending on the permissions of the user account running the atomic-agents-stack process. Organizations deploying this dashboard on non-loopback interfaces or in environments with co-located untrusted services are at a significantly higher risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade atomic-agents-stack to a version where file serving paths are routed through the \u003ccode\u003e_io.safe_resolve_under\u003c/code\u003e function and path traversal sequences are rejected.\u003c/li\u003e\n\u003cli\u003eAudit deployment configurations to ensure the HTTP dashboard server is bound only to the loopback interface (127.0.0.1) unless specific, authenticated network access is required.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the dashboard's listening port to authorized management IP addresses only.\u003c/li\u003e\n\u003cli\u003eDeploy web server or proxy logs monitoring for URI patterns containing directory traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e) directed at the dashboard endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T14:21:25Z","date_published":"2026-08-13T14:21:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-atomic-agents-path-traversal/","summary":"The atomic-agents-stack dashboard HTTP server lacks sufficient path validation, enabling unauthenticated attackers to read arbitrary files from the underlying filesystem.","title":"Path Traversal in atomic-agents-stack Dashboard HTTP Server","url":"https://feed.craftedsignal.io/briefs/2026-08-atomic-agents-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Atomic-Agents-Stack (1.0.0)","version":"https://jsonfeed.org/version/1.1"}