CVE-2026-2256: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-2256 is a command injection vulnerability in ModelScope's MS-Agent framework (ms-agent) affecting versions v1.6.0rc1 and earlier (specifically confirmed in v1.5.2). It allows an attacker to execute arbitrary operating system commands by injecting crafted content into prompt-derived input processed by the agent's Shell tool. The vulnerability was reported by Itamar Yochpaz, notified to the vendor on 2026-01-15, and publicly disclosed on 2026-03-02. It carries a CVSS v3.1 base score of 6.5 (Medium) (CERT/CC VU#431821, Feedly).

Technical details

The root cause is improper neutralization of special elements used in a command (CWE-77). The MS-Agent Shell tool (ms_agent/tools/shell/shell.py) uses a regex-based denylist in its check_safe() method to block dangerous commands such as sudo, rm -rf /, and curl | bash. However, this denylist is incomplete and can be bypassed using alternative interpreters (e.g., python3, nc, perl, ruby, node) that are not blocked, allowing arbitrary code execution. An attacker exploits this via indirect prompt injection — embedding malicious command sequences in attacker-controlled content (documents, web pages, logs, research inputs) that the agent is instructed to process, causing the agent to forward injected commands to the Shell tool without direct shell access. A public PoC demonstrating reverse shell establishment via python3 bypass is available (CERT/CC VU#431821, PoC Repo).

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands with the privileges of the MS-Agent process on the host system, potentially leading to full host compromise. Consequences include modification of system files, exfiltration of sensitive data accessible to the agent process, establishment of persistence mechanisms (e.g., reverse shells), and lateral movement within the environment. Because the agent may operate with broad permissions to perform autonomous tasks, the blast radius can extend well beyond the agent process itself (CERT/CC VU#431821, PoC Repo).

Exploitability

A public proof-of-concept exploit (reverse_shell_poc.py) is available on GitHub, demonstrating bypass of the check_safe() denylist to establish a reverse shell via python3 (PoC Repo). The vulnerability requires no authentication, no user interaction, and no special privileges — exploitation is achievable by any attacker who can influence content ingested by the agent (e.g., via a malicious document, webpage, or prompt). The EPSS score is approximately 0.023 (2.3%), indicating moderate automated exploitation probability. No confirmed in-the-wild exploitation or CISA KEV catalog listing has been reported as of the available data. No specific threat actor attribution has been identified (Feedly).

Exploitation steps

  1. Reconnaissance: Identify deployments of MS-Agent (versions ≤ v1.6.0rc1) that are configured with the Shell tool enabled and that process external or user-supplied content (documents, URLs, chat prompts, research inputs).
  2. Craft malicious payload: Prepare attacker-controlled content (e.g., a document, webpage, or prompt) containing an indirect prompt injection payload that instructs the agent to execute a shell command using a non-blocked interpreter, such as: python3 -c 'import socket,subprocess,os; ...' (reverse shell payload).
  3. Deliver payload: Introduce the malicious content into a data source the agent will process — for example, a publicly accessible document the agent is asked to summarize, a URL it is asked to fetch, or a crafted chat message.
  4. Trigger agent execution: The agent processes the attacker-controlled content and, following the embedded instructions, passes the injected command to the Shell tool's check_safe() method.
  5. Bypass denylist: The injected command uses python3 or another interpreter not present in the blocklist, causing check_safe() to pass validation.
  6. Achieve code execution: The Shell tool executes the command with the privileges of the MS-Agent process, establishing a reverse shell or performing other attacker-defined actions on the host (CERT/CC VU#431821, PoC Repo).

Indicators of compromise

  • Process: Unexpected child processes spawned by the MS-Agent Python process, particularly python3 -c, nc, perl, ruby, or node with network-related arguments; processes establishing outbound connections on unusual ports (e.g., 1111, 4444).
  • Network: Outbound TCP connections from the MS-Agent host to unknown external IPs on non-standard ports; reverse shell traffic patterns (interactive shell over raw TCP).
  • File System: New or modified files in /tmp/ or the MS-Agent working directory created by the agent process; unexpected scripts or executables dropped by the agent.
  • Logs: MS-Agent execution logs showing shell commands containing python3 -c, import socket, subprocess, or other interpreter-based payloads; log entries showing check_safe() being called with unusual command strings.
  • Persistence: New cron jobs, systemd services, or startup scripts created under the MS-Agent process account (CERT/CC VU#431821, PoC Repo).

Mitigation and workarounds

No official patch from ModelScope was obtained during the CERT/CC coordination process, and no vendor statement has been issued. CERT/CC recommends the following mitigations: (1) Deploy MS-Agent only in environments where all ingested content is trusted, validated, or sanitized prior to processing. (2) Replace the denylist-based check_safe() filtering with a strict allowlist of permitted commands. (3) Run MS-Agent with least-privilege OS permissions to limit the impact of exploitation. (4) Sandbox or containerize the MS-Agent process to restrict its access to host resources and the network. Users should monitor the MS-Agent GitHub repository for a patched release and upgrade as soon as one is available (CERT/CC VU#431821).

Community reactions

The vulnerability received notable coverage across security media outlets including GBHackers, CyberSecurityNews, eSecurity Planet, and The Hacker News (weekly recap), highlighting the novel attack surface of indirect prompt injection in agentic AI frameworks (GBHackers, CyberSecurityNews, The Hacker News). Security researchers noted the broader implications for autonomous AI agent security, with Checkmarx referencing it in their AppSec weekly recap and Purple Ops publishing analysis on autonomous AI agent security risks (Checkmarx, Purple Ops). The OWASP AISVS project referenced the vulnerability in pull requests, indicating it is being used to inform AI security verification standards (OWASP AISVS). Community discussion on Reddit and Bluesky reflected concern about the ease of exploitation via prompt injection in AI agent frameworks.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management