github.com
https://github.com/modelscope/agentscope CVE-2024-8537
CRITICAL
Path Traversal in modelscope/agentscope
Record summary
CVE-2024-8537 has a selected CVSS score of 9.1 (critical).
Description
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
modelscope/agentscopeBrowse modelscope / modelscope/agentscope | CVE List | Through latest | affected |
agentscopeBrowse PyPI / agentscope | GitHub Advisory | Through 0.1.1 | affected |
References
6github.com
https://github.com/modelscope/agentscope/blob/01530ee6a99c86426aab1be11ec3b3b86ca640ac/src/agentscope/studio/_app.py github.com
https://github.com/modelscope/agentscope/commit/7d285e862f86fa1d96ed04c4cd40a5f1b8f9189a github.com
https://github.com/modelscope/agentscope/pull/459 huntr.com
https://huntr.com/bounties/eeb8aa4b-e6e5-465c-b0dd-aa97e3b7dc09 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8537