Medium severity6.1NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-8556
CVE-2024-8556
Description
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
agentscopePyPI | <= 0.1.1 | — |
Affected products
3cpe:2.3:a:modelscope:agentscope:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:modelscope:agentscope:*:*:*:*:*:*:*:*range: <=2024-08-09
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/8439f16b-5256-4466-bb7d-371572572a4bnvdExploitWEB
- github.com/advisories/GHSA-6mf6-7j75-2m6fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8556ghsaADVISORY
- github.com/modelscope/agentscope/blob/21161fe9985ee2a2f617180b00a1424b81302d42/src/agentscope/studio/static/js/dashboard.jsghsaWEB
News mentions
0No linked articles in our index yet.