CVE-2026-51568
- EPSS 0.32%
- Veröffentlicht 30.09.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 17:17:25
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
CVE-2026-51570
- EPSS 0.23%
- Veröffentlicht 30.09.2026 00:00:00
- Zuletzt bearbeitet 02.10.2026 13:17:45
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
CVE-2026-6606
- EPSS 0.28%
- Veröffentlicht 20.04.2026 04:45:11
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side r...
CVE-2026-6605
- EPSS 0.33%
- Veröffentlicht 20.04.2026 04:30:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-s...
CVE-2026-6604
- EPSS 0.28%
- Veröffentlicht 20.04.2026 04:15:11
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cloud Metadat...
CVE-2026-6603
- EPSS 0.31%
- Veröffentlicht 20.04.2026 04:00:20
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This manipulation causes code injection...
CVE-2024-8487
- EPSS 0.28%
- Veröffentlicht 20.03.2025 10:11:26
- Zuletzt bearbeitet 01.04.2025 20:32:06
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make reque...
CVE-2024-8556
- EPSS 0.41%
- Veröffentlicht 20.03.2025 10:11:21
- Zuletzt bearbeitet 01.04.2025 20:31:16
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run...
CVE-2024-8524
- EPSS 1.14%
- Veröffentlicht 20.03.2025 10:11:18
- Zuletzt bearbeitet 15.10.2025 13:15:54
A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.
CVE-2024-8537
- EPSS 0.99%
- Veröffentlicht 20.03.2025 10:11:00
- Zuletzt bearbeitet 01.08.2025 01:50:54
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue aris...