CVE-2024-8556

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2024-8556 is a stored cross-site scripting (XSS) vulnerability identified in the modelscope/agentscope repository, specifically in the latest commit 21161fe on the main branch. The flaw lies in the view for inspecting detailed run information, where user-controllable strings, namely run IDs, are appended and rendered as HTML without proper sanitization. As a result, an attacker can inject and execute arbitrary JavaScript code in the user's browser context, leading to potential information disclosure or further exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share