Path Traversal Vulnerability in Atomic Agents Stack by Dep0we
CVE-2026-91989

8.7HIGH

Key Information:

Vendor

Dep0we

Vendor
CVE Published:
15 September 2026

What is CVE-2026-91989?

The Atomic Agents Stack prior to version 1.1.0 is susceptible to a path traversal vulnerability that can be exploited via the dashboard's HTTP server. By manipulating request paths with directory traversal sequences such as '../', attackers can access files beyond the designated agents_root directory. This flaw enables unauthorized remote file access, compromising the integrity and confidentiality of sensitive information stored on the server. Proper validation and sanitization of request paths is crucial to mitigate such vulnerabilities.

Affected Version(s)

atomic-agents-stack 0 < 1.1.0

atomic-agents-stack 1.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.