Beveiligingsadvies

CVE-2026-85685

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 14:32:31
Laatst bijgewerkt 2026-09-04 15:11:39
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing.