📦 Agentscope

by Modelscope

🔍 What is Agentscope?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8487

CRITICAL CVSS 9.8 Mar 20, 2025

This CVE describes a Cross-Origin Resource Sharing (CORS) misconfiguration in modelscope/agentscope v0.0.4 that allows any external domain to make requests to the API. This vulnerability enables unaut...

CVE-2024-8537

CRITICAL CVSS 9.1 Mar 20, 2025

A path traversal vulnerability in modelscope/agentscope's /delete-workflow endpoint allows attackers to delete arbitrary files from the filesystem by manipulating file paths. This affects all versions...

CVE-2024-48050

CRITICAL CVSS 9.8 Nov 4, 2024

This vulnerability allows unauthenticated remote code execution in agentscope workflow utilities. Attackers can execute arbitrary commands through the eval() function in is_callable_expression. All us...

CVE-2024-8438

HIGH CVSS 7.5 Mar 20, 2025

A path traversal vulnerability in modelscope/agentscope v0.0.4 allows attackers to read arbitrary files on the server by manipulating the 'path' parameter in the /api/file endpoint. This affects all d...

CVE-2024-8501

HIGH CVSS 8.8 Mar 20, 2025

This vulnerability allows any user to download arbitrary files from the rpc_agent's host system by exploiting the download_file method in modelscope/agentscope. This can lead to unauthorized access to...

CVE-2024-8556

MEDIUM CVSS 6.1 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in modelscope/agentscope allows attackers to inject malicious JavaScript via user-controllable run IDs. This code executes in victims' browsers when t...