Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8537

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:modelscope:agentscope:*:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00737
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-29

Связанные уязвимости

CVSS3: 9.1
github
11 месяцев назад

AgentScope path traversal vulnerability

EPSS

Процентиль: 72%
0.00737
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-29