MEDIUM6.1
PYSEC-2026-1076
AgentScope stored cross-site scripting (XSS) vulnerability
Details
A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/agentscope
Introduced in:
0No fixed version published yet for agentscope (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-8556[ADVISORY]
- https://github.com/modelscope/agentscope[PACKAGE]
- https://github.com/modelscope/agentscope/blob/21161fe9985ee2a2f617180b00a1424b81302d42/src/agentscope/studio/static/js/dashboard.js#L90[WEB]
- https://huntr.com/bounties/8439f16b-5256-4466-bb7d-371572572a4b[WEB]
- https://pypi.org/project/agentscope[PACKAGE]
- https://github.com/advisories/GHSA-6mf6-7j75-2m6f[ADVISORY]