threat
engine
.sh
Back
·
··:··
Home
/
Product
/
modelscope agentscope
Product
modelscope agentscope
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-8556
<= 2024-08-09
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main bra
6.1
MEDIUM
CVE-2024-8551
all versions
A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior
9.1
CRITICAL
CVE-2024-8537
all versions
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is prese
9.1
CRITICAL
CVE-2024-8524
all versions
A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to r
7.5
HIGH
CVE-2024-8501
all versions
An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vu
8.8
HIGH
CVE-2024-8487
all versions
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the
9.8
CRITICAL
CVE-2024-8438
all versions
A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint
/api/file
does not properly san
7.5
HIGH
CVE-2024-8550
all versions
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vul
7.5
HIGH
CVE-2024-48050
<= 0.0.4
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin