Path Traversal Vulnerability in Modelscope Agentscope by Modelscope
CVE-2024-8438
What is CVE-2024-8438?
A path traversal vulnerability has been identified in Modelscope's Agentscope product, specifically in version v0.0.4. This issue arises from inadequate sanitization of the path parameter in the API endpoint /api/file, which exposes the system to potential unauthorized access. An attacker could exploit this vulnerability to read sensitive files from the server, leading to potential data breaches and information leaks. Immediate mitigation is recommended to secure the application and prevent exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
modelscope/agentscope <= unspecified
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
