CVE-2024-8551: Path Traversal in modelscope/agentscope
A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8551?
CVE-2024-8551 is classified as a high-severity vulnerability due to its potential for allowing arbitrary file read and write operations.
How do I fix CVE-2024-8551?
To mitigate CVE-2024-8551, upgrade to modelscope/agentscope versions that contain the fix, ensuring you are running a version later than the affected versions.
What systems are affected by CVE-2024-8551?
CVE-2024-8551 affects modelscope/agentscope versions prior to the fix as well as pip package agentscope versions up to and including 0.1.1.
What type of vulnerability is CVE-2024-8551?
CVE-2024-8551 is a path traversal vulnerability that enables unauthorized access to the filesystem.
What are the potential impacts of CVE-2024-8551?
The potential impacts of CVE-2024-8551 include exposure of sensitive data and unauthorized modification of files on the filesystem.