Vulnerability Description
agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
References
- https://gist.github.com/Ro1ME/78910899a99e2ba702d588e477d0755f
- https://github.com/agentscope-ai/agentscope/issues/1645
FAQ
What is CVE-2026-51922?
CVE-2026-51922 is a documented vulnerability. agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command...
How severe is CVE-2026-51922?
CVSS scoring is not yet available for CVE-2026-51922. Check NVD for updates.
Is there a patch for CVE-2026-51922?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.