CVE-2024-8524: Directory Traversal in modelscope/agentscope
Published Mar 20, 2025
·Updated
A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.
Affected Software
3 affected components
pip/agentscope<=0.0.4
modelscope agentscope=0.0.4
modelscope agentscope
Event History
Mar 20, 2025
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
Affected Software
Advisory Published
via GitHub·12:32 PM
Data Sourced
via GitHub·12:32 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8524?
CVE-2024-8524 is categorized as a medium severity vulnerability due to its potential impact on sensitive local data.
2
How do I fix CVE-2024-8524?
To fix CVE-2024-8524, upgrade to the latest version of modelscope/agentscope that addresses the directory traversal vulnerability.
3
What systems are affected by CVE-2024-8524?
CVE-2024-8524 affects modelscope/agentscope version 0.0.4.
4
Can CVE-2024-8524 be exploited remotely?
Yes, CVE-2024-8524 can be exploited remotely by sending a crafted POST request to the /read-examples endpoint.
5
What type of files can be accessed through CVE-2024-8524?
CVE-2024-8524 allows attackers to read any local JSON file on the affected system.