CVE-2024-8502

CVSS 3.0 Score 9.8 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 502

Summary

CVE-2024-8502 is a newly disclosed vulnerability affecting modelscope/agentscope version 0.0.6a3. This issue permits remote code execution (RCE) due to deserialization vulnerabilities in the RpcAgentServerLauncher class. Specifically, the AgentServerServicer's create_agent method deserializes untrusted input using the dill library, making it susceptible to attack. An adversary can exploit this weakness to execute arbitrary commands on the targeted server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share