Vulnerability Description
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Itamar-Yochpaz/CVE-2026-2256-PoC
- https://github.com/modelscope/ms-agent
- https://medium.com/@itamar.yochpaz/cve-2026-2256-from-ai-prompt-to-full-system-c
- https://www.hiddenlayer.com/research/indirect-prompt-injection-of-claude-compute
- https://www.kb.cert.org/vuls/id/431821
FAQ
What is CVE-2026-2256?
CVE-2026-2256 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived inp...
How severe is CVE-2026-2256?
CVE-2026-2256 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2256?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.