Skip to content
agentscopeGHSA-6p55-qr3j-mpgq

AgentScope uses `eval`

High9.8CVE-2024-48050 · Published Nov 5, 2024 · updated May 20, 2026

In agentscope <=v0.0.4, the file `agentscope\web\workstation\workflow_utils.py` has the function `is_callable_expression`. Within this function, the line `result = eval(s)` poses a security risk as it can directly execute user-provided commands.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.1.0No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope arbitrary file download vulnerability in rpc_agent_client
High7.5Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical9.1Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
agentscope: attacker could read arbitrary files
High7.5Feb 10, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.