THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rm43-82j9-r4mj (high) — atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

[GHSA] GHSA-rm43-82j9-r4mj (high) — atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

medgithub_advisoriesPublished 2026-08-13

GHSA-rm43-82j9-r4mj Severity: high CVE: None

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

The optional dashboard HTTP server (`atomic_agents/dashboard/serve.py`) builds filesystem paths directly from the request path and serves them without a containment check. It is the only per-request untrusted-path site in the codebase that does not route through `_io.

Original source: https://github.com/advisories/GHSA-rm43-82j9-r4mj