logo

CVE-2026-2256: Unpatched Flaw in MS-Agent Lets Hackers Hijack AI Assistants

ID: 6d2f3020-28be-543a-baad-672ef6d019b5

STIX ID: report--6d2f3020-28be-543a-baad-672ef6d019b5

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ddos

...
...

The article reports CVE-2026-2256 in the MS-Agent framework: a prompt-injection vulnerability in the agent's Shell tool and its denylist-based check_safe() allows attackers to bypass filters and execute arbitrary OS commands via poisoned text inputs, potentially enabling data theft, system compromise, lateral movement and persistence. No vendor patch is available; recommended mitigations include running agents in sandboxes and replacing denylists with strict allowlists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.