CVE-2026-2256: Command injection vulnerability in ModelScope's ms-agent
Published Mar 2, 2026
·Updated
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
Affected Software
1 affected component
modelscope ms-agent<1.6.0rc1
Event History
Mar 2, 2026
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-2256?
CVE-2026-2256 is classified as a high severity command injection vulnerability.
2
How does CVE-2026-2256 allow exploitation?
CVE-2026-2256 allows an attacker to execute arbitrary operating system commands through crafted input.
3
Which versions of ModelScope's ms-agent are affected by CVE-2026-2256?
CVE-2026-2256 affects ModelScope's ms-agent versions up to and including v1.6.0rc1.
4
How can I mitigate CVE-2026-2256?
To mitigate CVE-2026-2256, upgrade to a patched version of ModelScope's ms-agent beyond v1.6.0rc1.
5
What are the potential impacts of CVE-2026-2256?
The impacts of CVE-2026-2256 may include unauthorized command execution and potential full system compromise.