CVE-2026-85685
Received Received - Intake

Path Traversal in AgentScope via LocalWorkspace.add_skill

Vulnerability report for CVE-2026-85685, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
agentscope agentscope to 2.0.7.post1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in AgentScope through version 2.0.7.post1. It exists in the LocalWorkspace.add_skill function where the skill_path parameter is not properly validated. Attackers can supply any directory path, causing the system to copy arbitrary server directories into the agent workspace. These files then become accessible through the workspace skill listing.

Detection Guidance

Check AgentScope logs for unusual file copy operations or requests to the add_skill endpoint. Inspect the skills directory for unexpected files or directories. Monitor network traffic for unrecognized HTTP requests to the LocalWorkspace.add_skill function.

Impact Analysis

This vulnerability allows attackers to copy sensitive server files into the workspace. They can read these files back through the skills listing, leading to server-side file disclosure. The lack of authentication in the HTTP API further enables unauthenticated access, making it easier for attackers to exploit this issue.

Mitigation Strategies

Upgrade AgentScope to a patched version beyond 2.0.7.post1. Implement strict path validation for the skill_path parameter to restrict copying to allowed directories. Add authentication to the add_skill API endpoint to prevent unauthenticated access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85685. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart