Skip to content
agentscopeGHSA-c4cc-w454-4634

AgentScope path traversal vulnerability

Critical9.1CVE-2024-8537 · Published Mar 20, 2025 · updated Jun 29, 2026

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.1.1No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical9.1Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.