Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4cc-w454-4634

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

AgentScope path traversal vulnerability

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

Пакеты

Наименование

agentscope

pip
Затронутые версииВерсия исправления

<= 0.1.1

Отсутствует

EPSS

Процентиль: 72%
0.00737
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-29

Связанные уязвимости

CVSS3: 9.1
nvd
11 месяцев назад

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

EPSS

Процентиль: 72%
0.00737
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-29