GHSA-f4hc-q562-cc5rHighCVSS 7.5
AgentScope Path Traversal in /api/file
🔗 CVE IDs covered (1)
📋 Description
A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint /api/file does not properly sanitize the path parameter, allowing an attacker to read arbitrary files on the server.
🎯 Affected products1
- pip/agentscope:<= 0.0.4
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2024-8438
- https://huntr.com/bounties/3f170c58-42ee-422d-ab6f-32c7aa05b974
- https://github.com/modelscope/agentscope/blob/af8e45ded37b3834c981473b309239e0102473d0/src/agentscope/studio/_app.py#L578
- https://github.com/pypa/advisory-database/tree/main/vulns/agentscope/PYSEC-2025-80.yaml
- https://github.com/advisories/GHSA-f4hc-q562-cc5r