Description
A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/3f170c58-42ee-422d-ab6f-32c7aa05b974
Scores
CVSS v3
7.5
EPSS
0.0039
EPSS Percentile
60.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
modelscope/agentscope
0.0.4
pypi/agentscope
0PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026