CVE-2026-2256: Modelscope Ms-Agent
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
Affected products
- Modelscope Ms-Agent: up to and including v1.6.0rc1
Published 2026-03-02. Last modified 2026-06-17.