id: PYSEC-2026-2668 published: "2026-07-13T14:36:40.119155Z" modified: "2026-07-13T16:04:59.724764Z" aliases: - CVE-2026-2256 - GHSA-4gc2-344q-r2rw summary: MS-Agent vulnerable to Command Injection details: A Command Injection vulnerability in ModelScope's MS-Agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input. affected: - package: name: ms-agent ecosystem: PyPI purl: pkg:pypi/ms-agent ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 1.6.0rc1 versions: - 0.0.0 - 1.0.0 - 1.0.0rc0 - 1.0.1rc0 - 1.1.0 - 1.1.1 - 1.1.2 - 1.2.0 - 1.3.0 - 1.4.0 - 1.5.0 - 1.5.1 - 1.5.2 - 1.6.0rc0 - 1.6.0rc1 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-2256 - type: WEB url: https://github.com/Itamar-Yochpaz/CVE-2026-2256-PoC - type: PACKAGE url: https://github.com/modelscope/ms-agent - type: WEB url: https://medium.com/@itamar.yochpaz/cve-2026-2256-from-ai-prompt-to-full-system-compromise-a4114c718326 - type: WEB url: https://www.hiddenlayer.com/research/indirect-prompt-injection-of-claude-computer-use - type: WEB url: https://www.kb.cert.org/vuls/id/431821 - type: PACKAGE url: https://pypi.org/project/ms-agent - type: ADVISORY url: https://github.com/advisories/GHSA-4gc2-344q-r2rw severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N