Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Agentscope CRITICAL 9.1
CVE-2024-8551

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This v…

No fix yet
Fix from $2,300 2025-03-20
Agentscope MEDIUM 6.1
CVE-2024-8556

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerabil…

Fix: after 2024-08-09
Fix from $1,600 2025-03-20
Agentscope CRITICAL 9.8
CVE-2024-8487

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server …

No fix yet
Fix from $2,300 2025-03-20
Agentscope CRITICAL 9.1
CVE-2024-8537

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-w…

No fix yet
Fix from $2,300 2025-03-20
Agentscope HIGH 8.8
CVE-2024-8501

An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows …

No fix yet
Fix from $1,950 2025-03-20
Agentscope HIGH 7.5
CVE-2024-8438

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` pa…

No fix yet
Fix from $1,950 2025-03-20
Agentscope HIGH 7.5
CVE-2024-8524

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON …

No fix yet
Fix from $1,950 2025-03-20
Agentscope HIGH 7.5
CVE-2024-8550

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows a…

No fix yet
Fix from $1,950 2025-02-10
Agentscope CRITICAL 9.8
CVE-2024-48050

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line…

Fix: after 0.0.4
Fix from $2,300 2024-11-04