agentscope vulnerabilities
CVEs whose affected-version data names the agentscope package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-6606High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
▾ Twilightagentscope · agentscopeEPSS 0.28%via OSV
CVE-2026-6603High· 7.3AgentScope Vulnerable to Remote Code Injection
AgentScope Vulnerable to Remote Code Injection
▾ Twilightagentscope · agentscopeEPSS 0.31%via OSV
CVE-2026-6605High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
▾ Twilightagentscope · agentscopeEPSS 0.33%via OSV
CVE-2026-6604High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
▾ Twilightagentscope · agentscopeEPSS 0.28%via OSV
CVE-2024-8556Medium· 6.1AgentScope stored cross-site scripting (XSS) vulnerability
AgentScope stored cross-site scripting (XSS) vulnerability
▾ Sunlitagentscope · agentscopeEPSS 0.42%via OSV