A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.
References
Configurations
History
No history.
Information
Published : 2025-03-20 10:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-8524
Mitre link : CVE-2024-8524
CVE.ORG link : CVE-2024-8524
JSON object : View
Products Affected
modelscope
- agentscope
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
