CVE-2024-8537
published 2025-03-20CVE-2024-8537: A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow…
PriorityP357critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EPSS
0.95%
56.9th percentile
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| modelscope | agentscope | 0 – 0.1.1 | — |
| modelscope | modelscope_agentscope | unspecified – latest | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
AgentScope path traversal vulnerability
ghsa·2025-03-20
CVE-2024-8537 [CRITICAL] CWE-22 AgentScope path traversal vulnerability
AgentScope path traversal vulnerability
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.
OSV
AgentScope path traversal vulnerability
osv·2025-03-20
CVE-2024-8537 [CRITICAL] AgentScope path traversal vulnerability
AgentScope path traversal vulnerability
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-20
Published