Skip to content
agentscopeGHSA-p6h7-hfj2-vmcf

AgentScope arbitrary file download vulnerability in rpc_agent_client

High7.5CVE-2024-8501 · Published Mar 20, 2025 · updated Jun 5, 2026

An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting the download_file method. This can lead to unauthorized access to sensitive information, including configuration files, credentials, and potentially system files, which may facilitate further exploitation such as privilege escalation or lateral movement within the network.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.0.4No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-36
Also known as
CVE-2024-8501, PYSEC-2025-82

More agentscope advisories

All agentscope
Advisory
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical9.8Mar 20, 2025
AgentScope path traversal vulnerability
Critical9.1Mar 20, 2025
AgentScope Path Traversal in /api/file
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.