VDB
Sign up
MEDIUM6.5

PYSEC-2026-2668

MS-Agent vulnerable to Command Injection

Details

A Command Injection vulnerability in ModelScope's MS-Agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ms-agent
Introduced in: 0

No fixed version published yet for ms-agent (pip). Pin to a known-safe version or switch to an alternative.

References