YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0007

Incident record

AgentScope copied any directory on the server into an agent's workspace if asked

Severity
High
Status
Proof-of-concept
Type
Data Leak
Target
AgentScope through 2.0.7.post1
Actor
researcher
CVE
CVE-2026-85685

What happened

LocalWorkspace.add_skill's skill_path parameter is not confined to an approved directory, so a caller can copy arbitrary server directories into the agent workspace, making their contents readable through the workspace's skill listing. Scored CVSS 3.1 7.5; the cited issue remained open at the 10 September check. A released fix was not established from that report.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026