PT-2025-12231 · Unknown · Agentscope

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-8489

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions modelscope/agentscope version 21161fe
Description A Cross-Site Request Forgery (CSRF) issue exists due to overly permissive CORS headers in the AgentScope Studio backend server. This allows an attacker to access all backend endpoints, including the api/file endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.
Recommendations For version 21161fe, consider restricting access to the api/file endpoint and reviewing CORS headers to prevent overly permissive settings. As a temporary workaround, restrict access to the backend server to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8489

Affected Products

Agentscope