Skip to content
agentscopeGHSA-6mf6-7j75-2m6f

AgentScope stored cross-site scripting (XSS) vulnerability

Medium6.1CVE-2024-8556 · Published Mar 20, 2025 · updated Jul 7, 2026

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.1.1No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical9.1Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.