Skip to content
agentscopeGHSA-f4hc-q562-cc5r

AgentScope Path Traversal in /api/file

High7.5CVE-2024-8438 · Published Mar 20, 2025 · updated Jun 5, 2026

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.0.4No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical9.1Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.