CVE-2024-8487

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 346

Summary

CVE-2024-8487 is a Cross-Origin Resource Sharing (CORS) vulnerability affecting modelscope/agentscope version v0.0.4. The CORS misconfiguration on the agentscope server enables unauthorized access, allowing any external domain to make requests to the API. This can result in unauthorized data access, information disclosure, and potential further exploitation, putting the system's integrity and confidentiality at risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share