PT-2025-12232 · Unknown · Modelscope/Agentscope
Published
2025-03-20
·
Updated
2025-03-22
·
CVE-2024-8501
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
modelscope/agentscope version v0.0.4
Description
An arbitrary file download issue exists in the rpc agent client component, allowing any user to download files from the rpc agent's host by exploiting the
download file method. This can lead to unauthorized access to sensitive information, including configuration files, credentials, and potentially system files, which may facilitate further exploitation such as privilege escalation or lateral movement within the network.Recommendations
For modelscope/agentscope version v0.0.4, consider disabling the
download file method in the rpc agent client component until a patch is available to prevent unauthorized file downloads. Restrict access to sensitive files and directories to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modelscope/Agentscope