Логотип exploitDog
bind:CVE-2024-8537
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8537

Количество 2

Количество 2

nvd логотип

CVE-2024-8537

11 месяцев назад

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-c4cc-w454-4634

11 месяцев назад

AgentScope path traversal vulnerability

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8537

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.

CVSS3: 9.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-c4cc-w454-4634

AgentScope path traversal vulnerability

CVSS3: 9.1
1%
Низкий
11 месяцев назад

Уязвимостей на страницу