Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9rw-qm5f-r8xm

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

AgentScope path traversal vulnerability in save-workflow

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords.

Пакеты

Наименование

agentscope

pip
Затронутые версииВерсия исправления

<= 0.1.1

Отсутствует

EPSS

Процентиль: 47%
0.00239
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 9.1
nvd
11 месяцев назад

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords.

EPSS

Процентиль: 47%
0.00239
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-23