CVE-2026-6603: Remote Code Injection in ModelScope AgentScope
The National Vulnerability Database (NVD) has disclosed CVE-2026-6603, a high-severity (CVSS 7.3) remote code injection vulnerability affecting ModelScope AgentScope versions up to 1.0.18. Specifically, the flaw resides in the execute_python_code and execute_shell_command functions within src/AgentScope/tool/_coding/_python.py. This means an attacker can remotely inject and execute arbitrary code.
The implications are severe: unauthenticated, remote attackers can achieve arbitrary code execution, leading to potential system compromise, data exfiltration, or further network pivot. The NVD notes that exploit details have been publicly disclosed, increasing the urgency for mitigation. The vendor was reportedly unresponsive to early disclosure attempts.
Defenders must prioritize patching or isolating any ModelScope AgentScope deployments. Given the public exploit and remote attack vector, this isn’t a theoretical risk — it’s an active threat. Assume compromise if you haven’t patched.
What This Means For You
- If your organization uses ModelScope AgentScope, check immediately if your version is 1.0.18 or earlier. Prioritize patching to a remediated version. If patching isn't possible, isolate these systems from public access and implement strict network segmentation and egress filtering. Audit logs for any suspicious `execute_python_code` or `execute_shell_command` invocations from untrusted sources.
Related ATT&CK Techniques
🛡️ Detection Rules
3 rules · 6 SIEM formats3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.
CVE-2026-6603: Remote Code Injection in ModelScope AgentScope execute_python_code
Indicators of Compromise
| ID | Type | Indicator |
|---|---|---|
| CVE-2026-6603 | Vulnerability | CVE-2026-6603 |
| CVE-2026-6603 | Affected Product | modelscope agentscope |
Source & Attribution
| Source Platform | NVD |
| Channel | National Vulnerability Database |
| Published | April 20, 2026 at 08:16 UTC |
This content was AI-rewritten and enriched by Shimi's Cyber World based on the original source. All intellectual property rights remain with the original author.
Believe this infringes your rights? Submit a takedown request.