CVE-2024-8438

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 22

Summary

CVE-2024-8438 is a newly disclosed path traversal vulnerability impacting modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` fails to sanitize the `path` parameter, enabling attackers to read arbitrary files stored on the server. This issue could lead to unauthorized data access and potential data breaches. Users are strongly encouraged to update to the latest version of modelscope/agentscope to mitigate this risk. Failure to do so could expose sensitive information to unauthorized entities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share