Skip to content
agentscopeGHSA-cr24-fv3h-8cjm

AgentScope Vulnerable to Remote Code Injection

Medium7.3CVE-2026-6603 · Published Apr 20, 2026 · updated Jul 13, 2026

A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 1.0.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74
Also known as
CVE-2026-6603, PYSEC-2026-2331

More agentscope advisories

All agentscope
Advisory
AgentScope vulnerable to Server-Side Request Forgery
Medium7.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
Medium7.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
Medium7.3Apr 20
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.