GHSA-f4hc-q562-cc5rHighCVSS 7.5

AgentScope Path Traversal in /api/file

Published
March 20, 2025
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint /api/file does not properly sanitize the path parameter, allowing an attacker to read arbitrary files on the server.

🎯 Affected products1

  • pip/agentscope:<= 0.0.4

🔗 References (5)