Skip to content
agentscopeGHSA-8ggf-r3vm-p3jc

AgentScope vulnerable to Server-Side Request Forgery

Medium7.3CVE-2026-6605 · Published Apr 20, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 1.0.18No fix yet
Details and references

A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2026-6605, PYSEC-2026-2330

More agentscope advisories

All
DateAdvisory
Apr 20AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6604Medium7.3no fix yet
Apr 20AgentScope Vulnerable to Remote Code Injection
CVE-2026-6603Medium7.3no fix yet
Apr 20AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6606Medium7.3no fix yet
Mar 202025AgentScope stored cross-site scripting (XSS) vulnerability
CVE-2024-8556Medium6.1no fix yet
Mar 202025AgentScope directory traversal vulnerability in /read-examples
CVE-2024-8524High7.5no fix yet
Mar 202025AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
CVE-2024-8487High7.4no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.