Skip to main content

Vendor/product archive

modelscope / agentscope CVEs

Beta · best-effort

9 CVEs tagged to modelscope / agentscope4 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-8556

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for ins…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8551

Published Mar 20, 2025

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacke…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8537

Published Mar 20, 2025

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8524

Published Mar 20, 2025

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8501

Published Mar 20, 2025

An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8487

Published Mar 20, 2025

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict acc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8438

Published Mar 20, 2025

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8550

Published Feb 10, 2025

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48050

Published Nov 4, 2024

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a secu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1