PT-2026-22697 · Modelscope · Modelscope Ms-Agent

·

CVE-2026-2256

·

Published

2026-03-02

·

Updated

2026-07-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ModelScope ms-agent versions prior to v1.6.0rc1
Description A command injection issue exists in the ModelScope ms-agent framework, specifically within the Shell tool, due to improper input sanitization. The regular expression-based blacklist used to filter harmful commands is ineffective against crafted attacks. This allows an attacker to execute arbitrary operating system commands through crafted prompt-derived input or by injecting malicious content into data sources used by the agent, without requiring direct shell access. Successful exploitation can lead to full system compromise, including the exfiltration of sensitive data such as API keys and configuration files, and the modification of system configurations.
Recommendations For versions prior to v1.6.0rc1, replace the implemented blacklist filtering with stronger allowlist protocols. Limit the deployment of ms-agent to trusted environments where all input is considered safe and validated. Implement sandboxes and least-privilege permissions for agents with shell execution capabilities.

Exploit

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2256
GHSA-4GC2-344Q-R2RW
PYSEC-2026-2668

Affected Products

Modelscope Ms-Agent