


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command o…
Published:
19 april 2026 om 22:00:00
Alert date:
20 april 2026 om 06:02:31
Source:
nvd.nist.gov
Emerging Technologies, Supply Chain & Dependencies
A code injection vulnerability was discovered in ModelScope AgentScope up to version 1.0.18. The vulnerability affects the execute_python_code/execute_shell_command functions in the _python.py file. The flaw allows remote code injection attacks and has been publicly disclosed with available exploits. The vendor was notified but did not respond to the disclosure.
Technical details
Mitigation steps:
Affected products:
ModelScope AgentScope
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6603
https://gist.github.com/YLChen-007/c084d69aaeda6729f3988603f2b0ce6e
https://vuldb.com/submit/792223
https://vuldb.com/vuln/358238
https://vuldb.com/vuln/358238/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
