CVE-2024-8489

HIGH

modelscope/agentscope - Cross-Site Request Forgery via Permissive CORS Headers

Title source: llm
STIX 2.1

Description

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0021
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
modelscope/modelscope/agentscope unspecified - latest
Published Mar 20, 2025
Tracked Since Feb 18, 2026