Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AgentScope path traversal vulnerability in LocalWorkspace.add_skill

AgentScope through version 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that allows attackers to copy arbitrary server directories into the agent workspace via an unconfined source path parameter.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Attackers can copy arbitrary files into the skills directory, making them accessible through the workspace skill listing.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-gpf9-4466-gc5g