{"id":"CVE-2024-8556","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-8556","summary":"A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting…","details":"A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.","published":"2025-03-20T10:11:21.587Z","modified":"2025-03-20T13:05:54.203Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://huntr.com/bounties/8439f16b-5256-4466-bb7d-371572572a4b"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-03-20T13:05:54.203Z"}}