Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CORS Vulnerability in modelscope/agentscope
Vulnerability Description
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized data access, information disclosure, and potential further exploitation, thereby compromising the integrity and confidentiality of the system.
CVSS Information
N/A
Vulnerability Type
源验证错误
Vulnerability Title
AgentScope 安全漏洞
Vulnerability Description
AgentScope是ModelScope开源的一个应用程序。更简单地构建基于 LLM 的多智能体应用。 AgentScope v0.0.4版本存在安全漏洞,该漏洞源于CORS配置未正确限制访问,允许任何外部域向API发出请求,可能导致未经授权的数据访问和信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A