CVE-2026-2256: Modelscope Ms-Agent

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

Affected products

  • Modelscope Ms-Agent: up to and including v1.6.0rc1

Published 2026-03-02. Last modified 2026-06-17.