« Back to list

Modelscope

Modelscope Agentscope: vulnerabilities and CVEs

Modelscope Agentscope has 19 published vulnerabilities, 8 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.

CVEs19
Last 12 months8
Critical6
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-51570High (8.1)0.39%—Sep 30, 2026
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
CVE-2026-51856Critical (9.8)0.20%—Sep 30, 2026
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service…
CVE-2026-51568High (8.1)0.41%—Sep 30, 2026
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
CVE-2026-85685High (8.7)0.55%—Sep 4, 2026
AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can…
CVE-2026-6606Medium (5.5)0.47%—Apr 20, 2026
A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the…
CVE-2026-6605Medium (5.5)0.51%—Apr 20, 2026
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a…
CVE-2026-6604Medium (5.5)0.47%—Apr 20, 2026
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py…
CVE-2026-6603Medium (5.5)0.52%—Apr 20, 2026
A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This…
CVE-2024-8556Medium (6.1)0.42%—Mar 20, 2025
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where…
CVE-2024-8551Critical (9.1)1.0%—Mar 20, 2025
A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files…
CVE-2024-8537Critical (9.1)1.0%—Mar 20, 2025
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from…
CVE-2024-8524High (7.5)1.2%—Mar 20, 2025
A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.
CVE-2024-8502Critical (9.8)1.8%—Mar 20, 2025
A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the…
CVE-2024-8501High (8.8)1.0%—Mar 20, 2025
An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting…
CVE-2024-8489High (8.8)0.23%—Mar 20, 2025
A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on…
CVE-2024-8487Critical (9.8)0.29%—Mar 20, 2025
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing…
CVE-2024-8438High (7.5)0.76%—Mar 20, 2025
A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.
CVE-2024-8550High (7.5)0.52%—Feb 10, 2025
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including…
CVE-2024-48050Critical (9.8)0.81%—Nov 4, 2024
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System3
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services2
  4. T1059.006 Python1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Modelscope