Impact
A path traversal flaw exists in Agentscope’s insert_text_file function between versions 1.0.0 and 1.0.8. The flaw allows an attacker to craft file paths that cause the application to read or write files outside the intended directory. This can lead to disclosure of sensitive system files, alteration of configuration files, or execution of malicious code if the attacker can write to a script or binary path. The weakness corresponds to CWE-22.
Affected Systems
Versions 1.0.0 through 1.0.8 of Agentscope are affected. The vendor is not specified, so any installation of these releases that permits external input to the insert_text_file function is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is unavailable, and the issue is not listed in CISA KEV, indicating no known widespread exploitation. Attackers can exploit the flaw through the insert_text_file API, which is likely exposed to remote clients, enabling remote traversal and file manipulation. The likely attack vector is remote API invocation with a crafted path.
OpenCVE Enrichment