Tag
high
advisory
Modelscope Agentscope Code Injection Vulnerability (CVE-2026-6603)
2 rules 1 TTPA code injection vulnerability exists in modelscope agentscope up to version 1.0.18, specifically affecting the execute_python_code/execute_shell_command functions, allowing for remote code execution.
code-injection
remote-code-execution
agentscope
2r
1t
high
advisory
modelscope agentscope Server-Side Request Forgery Vulnerability (CVE-2026-6604)
3 rules 1 TTPA server-side request forgery vulnerability (CVE-2026-6604) exists in modelscope agentscope up to version 1.0.18, allowing remote attackers to manipulate the image_url or audio_file_url arguments to perform SSRF attacks via the Cloud Metadata Endpoint component.
agentscope
ssrf
cve-2026-6604
modelscope
3r
1t