Skip to content
agentscopeGHSA-6v28-q95m-93qr

AgentScope directory traversal vulnerability in /read-examples

High7.5CVE-2024-8524 · Published Mar 20, 2025 · updated Jun 5, 2026

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.0.4No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical9.1Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.