CVE-2024-8502
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 502
Summary
CVE-2024-8502 is a newly disclosed vulnerability affecting modelscope/agentscope version 0.0.6a3. This issue permits remote code execution (RCE) due to deserialization vulnerabilities in the RpcAgentServerLauncher class. Specifically, the AgentServerServicer's create_agent method deserializes untrusted input using the dill library, making it susceptible to attack. An adversary can exploit this weakness to execute arbitrary commands on the targeted server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.