Path Traversal Vulnerability in Modelscope Agentscope by Modelscope
CVE-2024-8438
7.5HIGH
What is CVE-2024-8438?
A path traversal vulnerability has been identified in Modelscope's Agentscope product, specifically in version v0.0.4. This issue arises from inadequate sanitization of the path parameter in the API endpoint /api/file, which exposes the system to potential unauthorized access. An attacker could exploit this vulnerability to read sensitive files from the server, leading to potential data breaches and information leaks. Immediate mitigation is recommended to secure the application and prevent exploitation of this vulnerability.
Affected Version(s)
modelscope/agentscope <= unspecified
