CVE-2026-2256: Unpatched Flaw in MS-Agent Lets Hackers Hijack AI Assistants
ID: 6d2f3020-28be-543a-baad-672ef6d019b5
STIX ID: report--6d2f3020-28be-543a-baad-672ef6d019b5
Feed Name: securityonline.info
Threat Score
The article reports CVE-2026-2256 in the MS-Agent framework: a prompt-injection vulnerability in the agent's Shell tool and its denylist-based check_safe() allows attackers to bypass filters and execute arbitrary OS commands via poisoned text inputs, potentially enabling data theft, system compromise, lateral movement and persistence. No vendor patch is available; recommended mitigations include running agents in sandboxes and replacing denylists with strict allowlists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
