Skip to content
agentscopePYSEC-2025-84

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue arise

High7.5CVE-2024-8550 · Published Feb 10, 2025 · updated May 21, 2026

Source advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 0.0.4No fix yet
Details and references

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue arises due to improper sanitization of user input passed to the os.path.join function, which can be exploited to access files outside the intended directory.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
the CVSS score
Also known as
CVE-2024-8550

More agentscope advisories

All
DateAdvisory
Mar 202025AgentScope stored cross-site scripting (XSS) vulnerability
CVE-2024-8556Medium6.1no fix yet
Mar 202025AgentScope directory traversal vulnerability in /read-examples
CVE-2024-8524High7.5no fix yet
Mar 202025AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
CVE-2024-8487High7.4no fix yet
Mar 202025AgentScope Deserialization Vulnerability
CVE-2024-8502Critical9.8no fix yet
Mar 202025AgentScope path traversal vulnerability
CVE-2024-8537Critical9.1no fix yet
Mar 202025AgentScope Path Traversal in /api/file
CVE-2024-8438High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.