ModelScope MS-Agent Command Injection Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A command injection vulnerability has been identified in ModelScope's MS-Agent framework, specifically in versions through 1.6.0rc1. The issue arises in the Shell tool component, where user-influenced input is not properly sanitized before being executed as operating system commands. This vulnerability allows an attacker to execute arbitrary commands on the host system with the same privileges as the MS-Agent process.

Impact

Exploitation of this vulnerability leads to arbitrary command execution on the host system, potentially allowing for full system compromise. Commands executed in this context can modify or delete files, access sensitive data such as API keys and tokens, and establish persistence mechanisms.

Reproduction

The vulnerability can be reproduced by injecting crafted input into prompts or documents that the MS-Agent framework will process. This input can include commands that bypass the application's regex-based filtering and are executed via the Shell tool.

Remediation

No official patch is available. Users are advised to deploy MS-Agent only in trusted environments and to sandbox agents with shell execution capabilities.

Added: Mar 2, 2026, 10:11 PM
Updated: Mar 2, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.5
remediation
0.0
relevance
3.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.