CVE-2024-8438: Modelscope Agentscope

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.

Affected products

Published 2025-03-20. Last modified 2026-06-17.