Back

MEDIUM

Command injection vulnerability in ModelScope's ms-agent

Published Mar 2, 2026

Description

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

Affected products

Remediation

Red Hat statement

This MODERATE impact command injection vulnerability affects Red Hat AI Inference Server and Red Hat OpenShift AI (RHOAI) through the ModelScope ms-agent component. An attacker can execute arbitrary operating system commands by providing specially crafted input derived from prompts.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Mar 2, 2026
Updated Mar 3, 2026
Reserved Feb 9, 2026
CISA Vulnrichment
Updated Mar 3, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 2, 2026
GHSA-4GC2-344Q-R2RW