Skip to content
agentscopeGHSA-j9rw-qm5f-r8xm

AgentScope path traversal vulnerability in save-workflow

Critical9.1CVE-2024-8551 · Published Mar 20, 2025 · updated Jun 29, 2026

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.1.1No fix yet
Details and references

More agentscope advisories

All agentscope
Advisory
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.