Skip to content
agentscopeGHSA-crx8-wpv6-jrj2

AgentScope vulnerable to Server-Side Request Forgery

Medium7.3CVE-2026-6606 · Published Apr 20, 2026 · updated Jul 13, 2026

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

GitHub advisory

Affected versions

PackageAffectedFixed in
agentscope
PyPI
<= 1.0.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2026-6606, PYSEC-2026-2332

More agentscope advisories

All agentscope
Advisory
AgentScope vulnerable to Server-Side Request Forgery
Medium7.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
Medium7.3Apr 20
AgentScope Vulnerable to Remote Code Injection
Medium7.3Apr 20
AgentScope stored cross-site scripting (XSS) vulnerability
Medium6.1Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High7.5Mar 20, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High7.4Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.