Vendor
high
advisory
Arbitrary Code Execution in ModelScope via Insecure PyYAML Parsing
2 TTPs 1 CVEModelScope insecurely utilizes the unsafe yaml.Loader to parse model configuration files, allowing an attacker to achieve arbitrary code execution by supplying a poisoned repository containing malicious Python object construction tags.
ModelScope
remote-code-execution
vulnerability
supply-chain
2t
1c
high
advisory
modelscope agentscope Server-Side Request Forgery Vulnerability (CVE-2026-6604)
3 rules 1 TTPA server-side request forgery vulnerability (CVE-2026-6604) exists in modelscope agentscope up to version 1.0.18, allowing remote attackers to manipulate the image_url or audio_file_url arguments to perform SSRF attacks via the Cloud Metadata Endpoint component.
agentscope
ssrf
cve-2026-6604
modelscope
3r
1t