Modelscope
Modelscope Agentscope: vulnerabilities and CVEs
Modelscope Agentscope has 19 published vulnerabilities, 8 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.
CVEs19
Last 12 months8
Critical6
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51570 | High (8.1) | 0.39% | — | Sep 30, 2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. |
| CVE-2026-51856 | Critical (9.8) | 0.20% | — | Sep 30, 2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service… |
| CVE-2026-51568 | High (8.1) | 0.41% | — | Sep 30, 2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. |
| CVE-2026-85685 | High (8.7) | 0.55% | — | Sep 4, 2026 | AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can… |
| CVE-2026-6606 | Medium (5.5) | 0.47% | — | Apr 20, 2026 | A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the… |
| CVE-2026-6605 | Medium (5.5) | 0.51% | — | Apr 20, 2026 | A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a… |
| CVE-2026-6604 | Medium (5.5) | 0.47% | — | Apr 20, 2026 | A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py… |
| CVE-2026-6603 | Medium (5.5) | 0.52% | — | Apr 20, 2026 | A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This… |
| CVE-2024-8556 | Medium (6.1) | 0.42% | — | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where… |
| CVE-2024-8551 | Critical (9.1) | 1.0% | — | Mar 20, 2025 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files… |
| CVE-2024-8537 | Critical (9.1) | 1.0% | — | Mar 20, 2025 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from… |
| CVE-2024-8524 | High (7.5) | 1.2% | — | Mar 20, 2025 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint. |
| CVE-2024-8502 | Critical (9.8) | 1.8% | — | Mar 20, 2025 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the… |
| CVE-2024-8501 | High (8.8) | 1.0% | — | Mar 20, 2025 | An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting… |
| CVE-2024-8489 | High (8.8) | 0.23% | — | Mar 20, 2025 | A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on… |
| CVE-2024-8487 | Critical (9.8) | 0.29% | — | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing… |
| CVE-2024-8438 | High (7.5) | 0.76% | — | Mar 20, 2025 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server. |
| CVE-2024-8550 | High (7.5) | 0.52% | — | Feb 10, 2025 | A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including… |
| CVE-2024-48050 | Critical (9.8) | 0.81% | — | Nov 4, 2024 | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.