CRITICAL
CORS Vulnerability in modelscope/agentscope
Published Mar 20, 2025
9.8
CRITICALCVSS 3.1
EPSS 0.29%
Description
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized data access, information disclosure, and potential further exploitation, thereby compromising the integrity and confidentiality of the system.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=latest
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Modelscope | Modelscope/agentscope | n/a |
|
- 0.0.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6907 Advisory
- https://github.com/advisories/GHSA-75v5-6885-59f9 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/agentscope/PYSEC-2025-81.yaml
- https://huntr.com/bounties/7aca7507-a94e-4e63-83a2-15648e5c4067 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2024-8487
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Reserved Sep 5, 2024
Link CVE-2024-8487
CISA Vulnrichment
Updated Mar 20, 2025
ENISA EUVD
EUVD-2025-6907 GHSA-75V5-6885-59F9 Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Exploited since n/a
Link EUVD-2025-6907