CVE Database
/

CVE-2026-2256

Back to search

CVE-2026-2256

Published: Mar 2, 2026

Modified: Mar 3, 2026

PUBLISHED

Description

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

VendorProductVersions

ModelScope

ms-agent

affected
0 - <= v1.6.0rc1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now