Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | — | — | Modelscope AgentscopeAI | 2/10/2026 | 2/10/2026 | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to… | |
| Aplazada | Alta (8.1) | 0.22% | — | Modelscope AgentscopeAI | 30/9/2026 | 2/10/2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | |
| Aplazada | Alta (8.1) | 0.32% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | |
| Aplazada | Alta (8.7) | 0.55% | — | Modelscope AgentscopeAI | 4/9/2026 | 23/9/2026 | AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills… | |
| Aplazada | Media (5.5) | 0.47% | — | Modelscope AgentscopeAI | 20/4/2026 | 17/6/2026 | A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (5.5) | 0.51% | — | Modelscope AgentscopeAI | 20/4/2026 | 17/6/2026 | A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 0.47% | — | Modelscope AgentscopeAI | 20/4/2026 | 17/6/2026 | A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cloud Metadata Endpoint. Such manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.52% | — | Modelscope AgentscopeAI | 20/4/2026 | 17/6/2026 | A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Media (6.1) | 0.42% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to… | |
| Modificada | Alta (7.5) | 1.2% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Modelscope AgentscopeAI | 20/3/2025 | 17/6/2026 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, where serialized input is deserialized using dill.loads, enabling… | |
| Analizada | Alta (8.8) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting the download_file method. This can lead to unauthorized access to sensitive information, including… | |
| Aplazada | Alta (8.8) | 0.23% | — | Modelscope AgentscopeAI | 20/3/2025 | 17/6/2026 | A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints,… | |
| Analizada | Crítica (9.8) | 0.29% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized data access,… | |
| Analizada | Alta (7.5) | 0.76% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server. | |
| Analizada | Alta (7.5) | 0.52% | — | Modelscope Agentscope | 10/2/2025 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue arises due to improper… | |
| Analizada | Crítica (9.8) | 0.81% | — | Modelscope Agentscope | 4/11/2024 | 17/6/2026 | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands. |