Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49rx-72gp-wfgj

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the api/file endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the api/file endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

EPSS

Процентиль: 9%
0.00034
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
11 месяцев назад

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

EPSS

Процентиль: 9%
0.00034
Низкий

8.8 High

CVSS3

Дефекты

CWE-352