GHSA-6v28-q95m-93qrHighCVSS 7.5

AgentScope directory traversal vulnerability in /read-examples

Published
March 20, 2025
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.

🎯 Affected products1

  • pip/agentscope:<= 0.0.4

🔗 References (5)