AgentScope path traversal vulnerability in LocalWorkspace.add_skill
AgentScope through version 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that allows attackers to copy arbitrary server directories into the agent workspace via an unconfined source path parameter.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Attackers can copy arbitrary files into the skills directory, making them accessible through the workspace skill listing.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-gpf9-4466-gc5g
