PT-2026-33711 · Modelscope · Agentscope

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6605

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions modelscope agentscope versions prior to 1.0.19
Description A flaw in the Internal Service component allows for server-side request forgery, which is a condition where an attacker can induce the server to make requests to an unintended location. This issue occurs within the get bytes from web url() function located in the src/agentscope/ utils/ common.py file and can be triggered remotely through manipulation.
Recommendations Update to a version newer than 1.0.18. As a temporary workaround, consider restricting the use of the get bytes from web url() function until a patch is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6605
GHSA-8GGF-R3VM-P3JC

Affected Products

Agentscope