Junglewise Threat Intelligence

CVE-2024-48050: PYSEC-2024-262 - In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function

CVE-2024-48050 · Severity: low · CVSS 3.1 · Published 2024-11-04

Technologies: agentscope (PyPI). Vendors: PyPI.

Executive brief

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.

Affected products

  • PyPI agentscope

Related threats