PatchSiren

agentscope-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH agentscope-ai CVE published 2026-09-04

CVE-2026-85685

CVE-2026-85685 is a path traversal vulnerability in AgentScope through 2.0.7.post1 that allows attackers to copy arbitrary server directories into the agent workspace. This vulnerability enables attackers to supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing. Defenders responsible for AgentScope [truncated]