A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
[ { "events": [ { "introduced": "0" }, { "last_affected": "crafted" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2256.json"