Description
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
Published: 2026-09-30
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the write_text_file routine of Agentscope, permitting an attacker to craft file paths that escape the intended storage directory. This path traversal vulnerability (CWE‑22) can lead to overwriting arbitrary files or creating files with attacker‑chosen content, potentially granting unauthorized data disclosure or modification. The severity rating of 8.1 indicates a substantial risk to confidentiality, integrity, and availability.

Affected Systems

Agentscope releases from version 1.0.0 through 1.0.18 are affected. Users running these versions should verify their installed component and consider an upgrade as soon as a fixed release becomes available.

Risk and Exploitability

The CVSS base score of 8.1 reflects high exploitability coupled with significant impact. No EPSS score is listed, so current public data does not indicate observed exploitation, and the vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit the flaw through any channel that invokes write_text_file, potentially with unauthenticated or weakly authenticated access, making the risk real if the application is exposed to untrusted input.

Generated by OpenCVE AI on September 30, 2026 at 23:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Agentscope to a patched version that resolves the path traversal defect, as recommended in the GitHub issue where the fix is published.
  • If an upgrade cannot be performed immediately, implement input validation to ensure any file path provided to write_text_file is strictly confined to the intended directory and reject paths containing traversal sequences such as '..' or absolute paths.
  • Enforce least‑privilege file system permissions for the runtime environment and, where possible, isolate the service in a sandbox with restricted write capabilities to contain the impact of a potential exploit.

Generated by OpenCVE AI on September 30, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Agentscope v1.0.0–1.0-18 Path Traversal Vulnerability
Weaknesses CWE-22

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:L/S:U/UI:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:45:34.069Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:10.993

Modified: 2026-09-30T21:17:10.993

Link: CVE-2026-51568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T00:00:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')