Modelscope / Agentscope
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-6606 | modelscope agentscope _agent_base.py _process_audio_block server-side request forgery | MEDIUM | 6.9 | Apr 20, 2026 |
| CVE-2026-6605 | modelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forgery | MEDIUM | 6.9 | Apr 20, 2026 |
| CVE-2026-6604 | modelscope agentscope Cloud Metadata Endpoint _openai_tools.py openai_audio_to_text server-side request forgery | MEDIUM | 6.9 | Apr 20, 2026 |
| CVE-2026-6603 | modelscope agentscope _python.py execute_shell_command code injection | MEDIUM | 6.9 | Apr 20, 2026 |
| CVE-2024-8487 | CORS Vulnerability in modelscope/agentscope | CRITICAL | 9.8 | Mar 20, 2025 |
| CVE-2024-8556 | Stored XSS in modelscope/agentscope | MEDIUM | 6.1 | Mar 20, 2025 |
| CVE-2024-8524 | Directory Traversal in modelscope/agentscope | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-8537 | Path Traversal in modelscope/agentscope | CRITICAL | 9.1 | Mar 20, 2025 |
| CVE-2024-8551 | Path Traversal in modelscope/agentscope | CRITICAL | 9.1 | Mar 20, 2025 |
| CVE-2024-8438 | Path Traversal in modelscope/agentscope | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2024-8501 | Arbitrary File Download in modelscope/agentscope | HIGH | 8.8 | Mar 20, 2025 |
| CVE-2024-8550 | Local File Inclusion (LFI) in modelscope/agentscope | HIGH | 7.5 | Feb 10, 2025 |
| CVE-2024-48050 | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result =… | HIGH | 8.9 | Nov 4, 2024 |
Showing 1 to 13 of 13 CVEs