Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6909 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser. |
Github GHSA |
GHSA-6mf6-7j75-2m6f | AgentScope stored cross-site scripting (XSS) vulnerability |
Tue, 01 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modelscope
Modelscope agentscope |
|
| CPEs | cpe:2.3:a:modelscope:agentscope:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modelscope
Modelscope agentscope |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser. | |
| Title | Stored XSS in modelscope/agentscope | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T13:05:54.203Z
Reserved: 2024-09-06T21:25:26.775Z
Link: CVE-2024-8556
Updated: 2025-03-20T13:05:46.582Z
Status : Analyzed
Published: 2025-03-20T10:15:43.230
Modified: 2025-04-01T20:31:16.397
Link: CVE-2024-8556
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA