PT-2026-22697 · Modelscope · Modelscope Ms-Agent
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ModelScope ms-agent versions prior to v1.6.0rc1
Description
A command injection issue exists in the ModelScope ms-agent framework, specifically within the Shell tool, due to improper input sanitization. The regular expression-based blacklist used to filter harmful commands is ineffective against crafted attacks. This allows an attacker to execute arbitrary operating system commands through crafted prompt-derived input or by injecting malicious content into data sources used by the agent, without requiring direct shell access. Successful exploitation can lead to full system compromise, including the exfiltration of sensitive data such as API keys and configuration files, and the modification of system configurations.
Recommendations
For versions prior to v1.6.0rc1, replace the implemented blacklist filtering with stronger allowlist protocols.
Limit the deployment of ms-agent to trusted environments where all input is considered safe and validated.
Implement sandboxes and least-privilege permissions for agents with shell execution capabilities.
Exploit
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modelscope Ms-Agent