PT-2026-33709 · Modelscope · Agentscope

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6603

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions modelscope agentscope versions prior to 1.0.19
Description A code injection flaw exists that allows remote attackers to execute arbitrary code. The issue is located in the execute python code() and execute shell command() functions within the 'src/AgentScope/tool/ coding/ python.py' file.
Recommendations Update to a version later than 1.0.18. As a temporary workaround, consider disabling the execute python code() and execute shell command() functions until a patch is applied.

Exploit

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6603
GHSA-CR24-FV3H-8CJM

Affected Products

Agentscope