MS-Agent Vulnerability Let Attackers Hijack AI Agent to Gain Full System Control
ID: 4b240e9c-16a2-5db5-b24e-8b81002099a1
STIX ID: report--4b240e9c-16a2-5db5-b24e-8b81002099a1
Feed Name: cybersecurityNews.com
Threat Score
A critical command-injection vulnerability (CVE-2026-2256) in the ModelScope MS-Agent framework allows attackers to exploit prompt-injection and the framework's unsanitized Shell tool to execute arbitrary OS commands remotely (CVSS 9.8), potentially leading to full system compromise; CERT/CC noted the vendor had not issued a patch and recommends immediate mitigations including sandboxing, least privilege, strict input validation, and allowlists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
