Description

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

INFO

Published Date :

2026-03-02T20:09:11.808Z

Last Modified :

2026-03-03T20:07:24.775Z

Source :

certcc
AFFECTED PRODUCTS

The following products are affected by CVE-2026-2256 vulnerability.

Vendors Products
Modelscope
  • Ms-agent

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact