Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6899 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords. |
Github GHSA |
GHSA-j9rw-qm5f-r8xm | AgentScope path traversal vulnerability in save-workflow |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 01 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:modelscope:agentscope:-:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords. | |
| Title | Path Traversal in modelscope/agentscope | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-15T12:50:41.115Z
Reserved: 2024-09-06T19:38:21.423Z
Link: CVE-2024-8551
Updated: 2025-03-20T17:51:46.982Z
Status : Analyzed
Published: 2025-03-20T10:15:43.097
Modified: 2025-08-01T12:44:30.457
Link: CVE-2024-8551
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:48Z
EUVD
Github GHSA