Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4gc2-344q-r2rw | MS-Agent vulnerable to Command Injection |
Thu, 05 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 04 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modelscope
Modelscope ms-agent |
|
| Vendors & Products |
Modelscope
Modelscope ms-agent |
Tue, 03 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Mon, 02 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 02 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input. | |
| Title | Command injection vulnerability in ModelScope's ms-agent | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-03-03T20:07:24.775Z
Reserved: 2026-02-09T15:23:17.916Z
Link: CVE-2026-2256
Updated: 2026-03-02T21:10:07.108Z
Status : Awaiting Analysis
Published: 2026-03-02T21:16:27.797
Modified: 2026-03-03T21:52:29.877
Link: CVE-2026-2256
OpenCVE Enrichment
Updated: 2026-04-21T23:45:02Z
Github GHSA