VendorsModelscopeagentscopeall versions
Vulnerabilities

Modelscope Agentscope

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-48050
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.
Published 2024-11-04 · Analyzed
9.8EPSS 0.008
CVE-2024-8487
CORS Vulnerability in modelscope/agentscope
Published 2025-03-20 · Analyzed
9.8EPSS 0.003
CVE-2024-8537
Path Traversal in modelscope/agentscope
Published 2025-03-20 · Analyzed
9.1EPSS 0.010
CVE-2024-8551
Path Traversal in modelscope/agentscope
Published 2025-03-20 · Analyzed
9.1EPSS 0.010
CVE-2024-8501
Arbitrary File Download in modelscope/agentscope
Published 2025-03-20 · Analyzed
8.8EPSS 0.010
CVE-2024-8524
Directory Traversal in modelscope/agentscope
Published 2025-03-20 · Modified
7.5EPSS 0.012
CVE-2024-8438
Path Traversal in modelscope/agentscope
Published 2025-03-20 · Analyzed
7.5EPSS 0.008
CVE-2024-8550
Local File Inclusion (LFI) in modelscope/agentscope
Published 2025-02-10 · Analyzed
7.5EPSS 0.005
CVE-2024-8556
Stored XSS in modelscope/agentscope
Published 2025-03-20 · Analyzed
6.1EPSS 0.004