Impact
The flaw resides in the write_text_file routine of Agentscope, permitting an attacker to craft file paths that escape the intended storage directory. This path traversal vulnerability (CWE‑22) can lead to overwriting arbitrary files or creating files with attacker‑chosen content, potentially granting unauthorized data disclosure or modification. The severity rating of 8.1 indicates a substantial risk to confidentiality, integrity, and availability.
Affected Systems
Agentscope releases from version 1.0.0 through 1.0.18 are affected. Users running these versions should verify their installed component and consider an upgrade as soon as a fixed release becomes available.
Risk and Exploitability
The CVSS base score of 8.1 reflects high exploitability coupled with significant impact. No EPSS score is listed, so current public data does not indicate observed exploitation, and the vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit the flaw through any channel that invokes write_text_file, potentially with unauthenticated or weakly authenticated access, making the risk real if the application is exposed to untrusted input.
OpenCVE Enrichment