Tools AI Risk Radar ai-incident-0007
Incident record
AgentScope copied any directory on the server into an agent's workspace if asked
- Severity
- High
- Status
- Proof-of-concept
- Type
- Data Leak
- Target
- AgentScope through 2.0.7.post1
- Actor
- researcher
- CVE
- CVE-2026-85685
What happened
LocalWorkspace.add_skill's skill_path parameter is not confined to an approved directory, so a caller can copy arbitrary server directories into the agent workspace, making their contents readable through the workspace's skill listing. Scored CVSS 3.1 7.5; the cited issue remained open at the 10 September check. A released fix was not established from that report.
Sources
- agentscope-ai/agentscope issue 2069github.com/agentscope-ai/agentscope/issues/2069
- NVD, CVE-2026-85685nvd.nist.gov/vuln/detail/CVE-2026-85685
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026