Executive brief
AgentScope is an open-source framework for building and running AI agents. The vulnerability allows attackers to copy arbitrary directories from a server into the agent workspace by manipulating the skill_path parameter, potentially exposing sensitive files or injecting malicious code into the workspace. This could compromise the integrity and confidentiality of agent operations and expose system data.
Technical details
A path traversal vulnerability exists in the LocalWorkspace.add_skill method in AgentScope through version 2.0.7.post1. The vulnerability stems from insufficient validation of the skill_path parameter, which is used to determine the source directory to copy into the workspace skills folder. An attacker can supply path traversal sequences or absolute paths to access and copy arbitrary directories from the server filesystem. The vulnerability is reachable via the workspace skill API without explicit authentication requirements, allowing an attacker with network access to the AgentScope service to enumerate and exfiltrate files. No patch information is currently available.
Affected products
- AgentScope AgentScope through 2.0.7.post1
Timeline
- 2026-09-04: disclosed