affected: - ecosystem_specific: {} package: ecosystem: PyPI name: agentscope purl: pkg:pypi/agentscope ranges: - events: - introduced: '0' - last_affected: 0.0.4 type: ECOSYSTEM versions: - 0.0.1 - 0.0.2 - 0.0.3 - 0.0.4 aliases: - CVE-2024-8524 - GHSA-6v28-q95m-93qr details: A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint. id: PYSEC-2025-83 modified: '2026-05-21T14:54:21.257001Z' published: '2025-03-20T10:15:42.853Z' references: - type: EVIDENCE url: https://huntr.com/bounties/cc4acf33-700d-4220-8a8a-db28f5c4cc8f - type: ADVISORY url: https://github.com/advisories/GHSA-6v28-q95m-93qr severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N type: CVSS_V3