Path Traversal Vulnerability in Modelscope Agentscope by Modelscope
CVE-2024-8438

7.5HIGH

Key Information:

Vendor

Modelscope

Vendor
CVE Published:
20 March 2025

What is CVE-2024-8438?

A path traversal vulnerability has been identified in Modelscope's Agentscope product, specifically in version v0.0.4. This issue arises from inadequate sanitization of the path parameter in the API endpoint /api/file, which exposes the system to potential unauthorized access. An attacker could exploit this vulnerability to read sensitive files from the server, leading to potential data breaches and information leaks. Immediate mitigation is recommended to secure the application and prevent exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

modelscope/agentscope <= unspecified

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.