logo

MS-Agent Vulnerability Exposes AI Agents to Remote Hijacking, Granting Full System Control

ID: 615a791e-ba27-56ea-b8a0-4be6384c6589

STIX ID: report--615a791e-ba27-56ea-b8a0-4be6384c6589

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Divya

...
...

A critical command-injection vulnerability (CVE-2026-2256) was disclosed in the ModelScope MS-Agent framework: its Shell tool’s check_safe() denylist can be bypassed via prompt-injection, allowing remote attackers to execute arbitrary OS commands with the agent’s privileges. No vendor patch was provided at disclosure; recommended mitigations include running agents in strict sandboxes, applying least-privilege, validating inputs, and replacing denylist filters with allowlists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.