CVE-2024-8556
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79
Summary
CVE-2024-8556 is a stored cross-site scripting (XSS) vulnerability identified in the modelscope/agentscope repository, specifically in the latest commit 21161fe on the main branch. The flaw lies in the view for inspecting detailed run information, where user-controllable strings, namely run IDs, are appended and rendered as HTML without proper sanitization. As a result, an attacker can inject and execute arbitrary JavaScript code in the user's browser context, leading to potential information disclosure or further exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.