CVE detail
CVE-2026-2256
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
Posted by sentra | 1 points | 0 comments
communitynews.ycombinator.comMar 13, 2026, 11:16 PMImproper input sanitization in the framework can be exploited through the Shell tool, allowing attackers to modify system files and steal data.
newswww.securityweek.comMar 3, 2026, 10:43 AM- https://www.kb.cert.org/vuls/id/431821www.kb.cert.org
No excerpt available.
Patchwww.kb.cert.orgMar 2, 2026, 9:16 PM - https://www.hiddenlayer.com/research/indirect-prompt-injection-of-claude-computer-usewww.hiddenlayer.com
No excerpt available.
Third Party Advisorywww.hiddenlayer.comMar 2, 2026, 9:16 PM No excerpt available.
Exploitmedium.comMar 2, 2026, 9:16 PM- https://github.com/modelscope/ms-agentgithub.com
No excerpt available.
Exploitgithub.comMar 2, 2026, 9:16 PM No excerpt available.
Exploitgithub.comMar 2, 2026, 9:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16763CVSS 1.9 · Low
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration…
- CVE-2024-58354CVSS 8.5 · High
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_ta…
- CVE-2026-47670CVSS 9.4 · Critical
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute…
- CVE-2026-16735CVSS 1.9 · Low
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Change…
- CVE-2026-16733CVSS 1.9 · Low
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handl…
- CVE-2026-16631CVSS 1.9 · Low
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. Th…