CVE-2026-91987: atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model
atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the estimatebatchcost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
atomic-agents-stackto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permission to configure a deployment and set its model identifier. The vulnerability can then be used with an identifier absent from the pricing table.
What is the operational impact?
Unknown model identifiers are estimated at zero cost, allowing daily cost caps to be bypassed. Parallel batch operations can consequently exceed intended budget limits.
Which versions should be remediated?
Versions of atomic-agents-stack before 1.1.0 are affected. Upgrade to 1.1.0 or later.