CVE-2026-51570 Details
Description
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
A directory traversal vulnerability has been identified in Modelscope Agentscope versions 1.0.18, 1.0.19, and 1.0.19.post1. The issue resides in the 'insert_text_file' function of the '_write_text_file.py' component. This vulnerability allows remote attackers to exploit validated paths to write files outside the designated workspace or storage boundaries.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/c6a6857348472db85895b346ba818195 | [email protected] | Technical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| modelscope Agentscope | >= 1.0.18, <= 1.0.19.post1 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion