Impact
AgentScope versions up to 2.0.7.post1 are vulnerable to a path traversal flaw in the LocalWorkspace.add_skill function. The flaw allows an attacker to provide any directory path in the skill_path request parameter, causing the server to copy the entire directory into the agent workspace, thereby arbitrarily exposing server files in the workspace skill listing.
Affected Systems
Affected vendors include agentscope-ai, product AgentScope, with all releases up to 2.0.7.post1 being impacted. All other later releases are considered fixed.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Attackers with network access can exploit the unconfined skill_path parameter, potentially without authentication, to copy any accessible directory into the workspace. While no EPSS score is available, the lack of KEV listing suggests no widespread exploitation yet, but the high CVSS warrants proactive mitigation. The ability to copy arbitrary files can be leveraged for data exfiltration or for inserting malicious content that may be executed later.
OpenCVE Enrichment