Description
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
Published: 2026-09-30
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Access / Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw exists in Agentscope’s insert_text_file function between versions 1.0.0 and 1.0.8. The flaw allows an attacker to craft file paths that cause the application to read or write files outside the intended directory. This can lead to disclosure of sensitive system files, alteration of configuration files, or execution of malicious code if the attacker can write to a script or binary path. The weakness corresponds to CWE-22.

Affected Systems

Versions 1.0.0 through 1.0.8 of Agentscope are affected. The vendor is not specified, so any installation of these releases that permits external input to the insert_text_file function is potentially vulnerable.

Risk and Exploitability

With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is unavailable, and the issue is not listed in CISA KEV, indicating no known widespread exploitation. Attackers can exploit the flaw through the insert_text_file API, which is likely exposed to remote clients, enabling remote traversal and file manipulation. The likely attack vector is remote API invocation with a crafted path.

Generated by OpenCVE AI on September 30, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a patch or upgrade Agentscope to a version newer than 1.0.8 once a vendor release fixes the path traversal flaw.
  • Configure the application or OS to restrict the directories that insert_text_file can access, removing write permissions to sensitive system paths.
  • Implement strict input validation to reject paths containing '..' or absolute paths before processing by the API.

Generated by OpenCVE AI on September 30, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Agentscope insert_text_file Function (v1.0.0–v1.0.8)
Weaknesses CWE-22

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:L/S:U/UI:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:46:52.177Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51570

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.137

Modified: 2026-09-30T21:17:11.137

Link: CVE-2026-51570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T00:00:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')