CVE-2024-8438: Modelscope Agentscope
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.
Affected products
- Modelscope Agentscope: version 0.0.4 only
Published 2025-03-20. Last modified 2026-06-17.