CVE-2026-51568 Details
Description
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
A directory traversal vulnerability has been identified in AgentScope versions 1.0.18 through 1.0.19.post1. This vulnerability allows remote attackers to write files outside the intended directory by exploiting the 'write_text_file' function in the 'src/agentscope/tool/_text_file/_write_text_file.py' file. The issue arises because the function does not validate file paths, leaving the system open to arbitrary file write attacks.
It is recommended to add path validation to the file operation functions to restrict file writes to within the user's workspace. This can be done by checking the file path against a base directory and rejecting any paths that traverse outside of it.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/6f26878766be5712ed504857c54492d7 | [email protected] | Technical Description |
| https://github.com/agentscope-ai/agentscope/issues/1508 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| modelscope Agentscope | >= 1.0.18, <= 1.0.19.post1 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion