CVE-2024-8551

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 23

Summary

CVE-2024-8551 is a newly disclosed path traversal vulnerability affecting modelscope/agentscope versions before the fix. This issue occurs in the save-workflow and load-workflow functions. An attacker can exploit this vulnerability to read and write arbitrary JSON files on the system, potentially gaining access to sensitive information like configuration files, API keys, and hardcoded passwords. The impact could be significant, as unauthorized modification of these files could disrupt services or allow unauthorized access to sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share