PT-2026-33710 · Modelscope · Agentscope

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6604

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function parse url/prepare image/openai audio to text of the file src/agentscope/tool/ multi modality/ openai tools.py of the component Cloud Metadata Endpoint. Such manipulation of the argument image url/audio file url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-6604

Affected Products

Agentscope