
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2256 is a command injection vulnerability in ModelScope's MS-Agent framework (ms-agent) affecting versions v1.6.0rc1 and earlier (specifically confirmed in v1.5.2). It allows an attacker to execute arbitrary operating system commands by injecting crafted content into prompt-derived input processed by the agent's Shell tool. The vulnerability was reported by Itamar Yochpaz, notified to the vendor on 2026-01-15, and publicly disclosed on 2026-03-02. It carries a CVSS v3.1 base score of 6.5 (Medium) (CERT/CC VU#431821, Feedly).
The root cause is improper neutralization of special elements used in a command (CWE-77). The MS-Agent Shell tool (ms_agent/tools/shell/shell.py) uses a regex-based denylist in its check_safe() method to block dangerous commands such as sudo, rm -rf /, and curl | bash. However, this denylist is incomplete and can be bypassed using alternative interpreters (e.g., python3, nc, perl, ruby, node) that are not blocked, allowing arbitrary code execution. An attacker exploits this via indirect prompt injection — embedding malicious command sequences in attacker-controlled content (documents, web pages, logs, research inputs) that the agent is instructed to process, causing the agent to forward injected commands to the Shell tool without direct shell access. A public PoC demonstrating reverse shell establishment via python3 bypass is available (CERT/CC VU#431821, PoC Repo).
Successful exploitation allows an attacker to execute arbitrary OS commands with the privileges of the MS-Agent process on the host system, potentially leading to full host compromise. Consequences include modification of system files, exfiltration of sensitive data accessible to the agent process, establishment of persistence mechanisms (e.g., reverse shells), and lateral movement within the environment. Because the agent may operate with broad permissions to perform autonomous tasks, the blast radius can extend well beyond the agent process itself (CERT/CC VU#431821, PoC Repo).
A public proof-of-concept exploit (reverse_shell_poc.py) is available on GitHub, demonstrating bypass of the check_safe() denylist to establish a reverse shell via python3 (PoC Repo). The vulnerability requires no authentication, no user interaction, and no special privileges — exploitation is achievable by any attacker who can influence content ingested by the agent (e.g., via a malicious document, webpage, or prompt). The EPSS score is approximately 0.023 (2.3%), indicating moderate automated exploitation probability. No confirmed in-the-wild exploitation or CISA KEV catalog listing has been reported as of the available data. No specific threat actor attribution has been identified (Feedly).
python3 -c 'import socket,subprocess,os; ...' (reverse shell payload).check_safe() method.python3 or another interpreter not present in the blocklist, causing check_safe() to pass validation.python3 -c, nc, perl, ruby, or node with network-related arguments; processes establishing outbound connections on unusual ports (e.g., 1111, 4444)./tmp/ or the MS-Agent working directory created by the agent process; unexpected scripts or executables dropped by the agent.python3 -c, import socket, subprocess, or other interpreter-based payloads; log entries showing check_safe() being called with unusual command strings.No official patch from ModelScope was obtained during the CERT/CC coordination process, and no vendor statement has been issued. CERT/CC recommends the following mitigations: (1) Deploy MS-Agent only in environments where all ingested content is trusted, validated, or sanitized prior to processing. (2) Replace the denylist-based check_safe() filtering with a strict allowlist of permitted commands. (3) Run MS-Agent with least-privilege OS permissions to limit the impact of exploitation. (4) Sandbox or containerize the MS-Agent process to restrict its access to host resources and the network. Users should monitor the MS-Agent GitHub repository for a patched release and upgrade as soon as one is available (CERT/CC VU#431821).
The vulnerability received notable coverage across security media outlets including GBHackers, CyberSecurityNews, eSecurity Planet, and The Hacker News (weekly recap), highlighting the novel attack surface of indirect prompt injection in agentic AI frameworks (GBHackers, CyberSecurityNews, The Hacker News). Security researchers noted the broader implications for autonomous AI agent security, with Checkmarx referencing it in their AppSec weekly recap and Purple Ops publishing analysis on autonomous AI agent security risks (Checkmarx, Purple Ops). The OWASP AISVS project referenced the vulnerability in pull requests, indicating it is being used to inform AI security verification standards (OWASP AISVS). Community discussion on Reddit and Bluesky reflected concern about the ease of exploitation via prompt injection in AI agent frameworks.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."