CVE-2026-2256
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
- Affected products
- Modelscope Ms-Agent
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.6% (74th percentile)
- Weakness
- CWE-77
- NVD status
- Awaiting Analysis
- Published
- 2026-03-02
CVE-2026-2256 at NVD
4 known exploits for CVE-2026-2256
Proof-of-concept code and exploit modules indexed by Sploitus