CVE-2024-8556Medium· 6.1▾ SunlitAgentScope stored cross-site scripting (XSS) vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.
agentscope <= 0.1.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6606High· 7.3AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6603High· 7.3AgentScope Vulnerable to Remote Code Injection
CVE-2026-6605High· 7.3AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6604High· 7.3AgentScope vulnerable to Server-Side Request Forgery